How to configure an FTP server with SSL protection

Source: Internet
Author: User
Tags ftp ftp client ftp protocol
Is it possible to set up an FTP server with SSL capabilities in the 5R2 version of the os/400 operating system?
  
The answer is yes. The ISeries FTP server supports both TLS (Transport Layer Security) and SSL (Secure Sockets Layer)-protected processes, including customer identification and automatic logon, to encrypt data transmitted over FTP control and data connections. Before you can set up your FTP server to use SSL, you must install the necessary programs and set up a digital certificate on your iseries server. However, before we examine how to set up your FTP server, it is important to understand the FTP protocol.
  
FTP uses two TCP connections, one connection for control, and another connection for data. The standard control connection uses TCP port 21, and the default data connection is Port 20. To start a secure FTP process, users can connect to TCP port 21 without encryption, and then negotiate the identification and encryption options. This process is called display control. On the other hand, when the user chooses a secure FTP port, the connection is implicitly connected, typically using 990 ports, and the connection on this port is Tls/ssl. The main reason for encrypting this control connection is to hide the password when you log on to the FTP server. Without a secure control connection, the FTP protocol does not allow you to have a secure data connection.
  
When you use TLS/SSL encryption for the control connection, the FTP client software is also encrypted for the data sent on the FTP data connection. Encryption has a high performance cost and can be bypassed in data connections to send unclassified files without reducing network performance, and can still protect the system by not exposing the password. The ISeries FTP server provides both options. To set up an FTP server with SSL capabilities on your iseries V5R2 server, you need to make sure that the server has the following software installed:
  
· os/400 operating system V5R2 version or above.
  
· TCP/IP Connection tool.
  
• 128-bit "cryptographic Access Provider" for iseries servers.
  
· IBM's digital certificate manager.
  
· IBM http Server.
  
Next you need to do the following:
  
1. Create a local certificate authority, or use the digital certificate Manager to set up an FTP server to use the public certificate associated with this FTP server.
  
2. The FTP server is required to identify the customer.
  
3. Enable the SSL feature on the FTP server. please contact the site, timely note your name. Contact Email: edu#chinaz.com (change # to @).



Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.