SSL and Cipher Requirements for RACF Connector Connections in CA Identity Suite
search cancel

SSL and Cipher Requirements for RACF Connector Connections in CA Identity Suite

book

Article ID: 220136

calendar_today

Updated On:

Products

CA Identity Suite CA Identity Manager

Issue/Introduction

This article addresses frequently asked questions regarding SSL and Cipher suite requirements when connecting the CA Identity Suite RACF connector to an underlying CA LDAP server.

Environment

Identity Manager 14.5 & 15

Resolution

The security requirements for connecting to an endpoint are dictated by the endpoint configuration itself rather than the Identity Manager software. Follow these steps to ensure a secure connection:

  1. Certificate Generation: Generate the required SSL certificate on the RACF/CA LDAP endpoint.
  2. Importing Certificates: Import the endpoint certificate into the Java Connector Server (JCS) keystore.
  3. Cipher Compatibility: The Java Connector Server supports any Cipher suite compatible with the Java Virtual Machine (JVM) it runs on. Cipher strength and selection are defined by the endpoint administrator and the JCS JVM security policy.
  4. Verification: If connection issues persist, verify that the JCS JVM is configured to support the specific Cipher suites required by your RACF endpoint security policy.

Additional Information

For detailed connector configuration, refer to the RACF v2 Connector - 14.5 or RACF v2 Connector - v15