Content Authors – SSL Connection—Author Dispatcher—SSL Connection—Author AEM
Prerequisites
The following are the required prerequisites for enabling SSL within AEM:
1. SSL Certificate
SSL Certificate, self-signed for development and signed CRT for production implementation
2. Private Key
Private key pertaining to the SSL certificate and in DER format
3. Apache Dispatcher Module w/ SSL support, latest web module from Adobe
dispatcher-apache2.4-4.2.2.sohttps://www.adobeaemcloud.com/content/companies/public/adobe/dispatcher/dispatcher.html
Technical Steps
The following are the steps for installing the SSL certificate in an AEM Author instance:
1. It is highly recommended to configure HTTPS now in any AEM Author instance and as part of this initiative; AEM lists “Configure HTTPS” as an active task that needs to be performed.
data:image/s3,"s3://crabby-images/b1ce5/b1ce5898485582ab6e39ddaac43f8c5db91939fa" alt=""
2. Click on the “Configure HTTPS” task and click on open to start the wizard. A service user called ssl-service has been created for this feature.
data:image/s3,"s3://crabby-images/8b5d2/8b5d2c27749e9aa7e3cf514a678ae6aa4b0165a8" alt=""
3. Type in a Key Store and Trust Store passwords. These are the Store credentials for the ssl-service system user's key store that will contain the private key and trust store for the HTTPS listener.
data:image/s3,"s3://crabby-images/4f7ab/4f7ab95c51fd557571040b92b9ee31a29f9eee84" alt=""
4. Upload the associated private key and internal signed CSR for the SSL connection.
data:image/s3,"s3://crabby-images/a628e/a628eb1a1cf477ccc8bb9f6a2e998acf96b4378f" alt=""
5. Select the HTTPS port. 8443 is the default TCP port for Author AEM HTTPS listener.
data:image/s3,"s3://crabby-images/80936/809364b8c3bf2b0660ba444339538cb0c6b5e79a" alt=""
6. You should get a success page stating that “SSL Successfully Configured”
data:image/s3,"s3://crabby-images/c316e/c316e9f75afe7229bbd86489a7ed79933dd0a5bd" alt=""
Validation
To validate that the proper certificate has been installed, please perform the following steps:
1. Go to AEM User Management and look for the service user, ssl-service.
2. In the Account Settings section, make sure that the status is set to “active”. Click on “Manage KeyStore” to view the certificate
data:image/s3,"s3://crabby-images/cf07a/cf07a39dbf4c1ec6bc11e0e53a0f5e826519ab89" alt=""
3. Confirm that the Certificate Subject, Issuer, and Expiry date are consistent with the CRT that was installed.
data:image/s3,"s3://crabby-images/4be65/4be65c7c8ea19996dee0ff3553e2e1a7664bf0d8" alt=""
Dispatcher/Apache Webserver
The following are the steps for installing the update dispatcher module and configuring the dispatcher to use the secure SSL channel:
1. Validate you have the right version of the dispatcher. If not, upload the updated dispatcher-apache2.4-4.2.2.so to the webserver (dispatcher).
2. Edit dispatcher.any file to use secure channel and SSL port
data:image/s3,"s3://crabby-images/99ff2/99ff2733842f9797cffa422e4bb250ea77f18bd7" alt=""
3. Restart Apache
4. Validate to test.
No comments:
Post a Comment
If you have any doubts or questions, please let us know.