KB Article #65692

What is the Expected Behavior for SSL/TLS Authentification property "Automatic import of partner certificate chains"

Problem

Environment
-------------------
SSL/TLS
Gateway 6.11.4 (client)
Transfer InterPEL 6.6.3 (server)



Question
-----------------------
* Configuration of SSL/TLS
* At Security Profile level there is an option "Automatic import of partner certificate chains"
* What is the expected behavior when checking and not checking this property ?
* What happens if above property is set but nothing is selected in "Trust hosted certificat only" ? Will this allow the client to import the partner certificate chain ?


Resolution

When the  "Automatic import of partner certificate chains" is checked :



-- If the option "Trust hosted certificat only" is set, ROOT certificates will be imported in the Gateway PKI base and can be used as accepted authorities for the certificats send by the partner.



-- If the option "Trust hosted certificat only" is not set, the only ROOT certificats which can be use as accepted authorities for the certificats send by the partner are the one checked in the "Accepted authorities" part of the security profile.