20.4.1 Prerequisites for SSL Communication between Identity Server and Access Gateway

If you are going to set up SSL communication between Identity Server and Access Gateway for authentication and you have configured Identity Server to use certificates created by an external CA, you need to import the public certificate of this CA into the trusted root keystore of Access Gateway.

  1. If you have not imported the public certificate of this CA into the trusted root store of Identity Server, do so now. For more information, see Importing Public Key Certificates (Trusted Roots).

  2. To add the public certificate to Access Gateway:

    1. Click Devices > Access Gateways > Edit > Service Provider Certificates > Trusted Roots

    2. In the Trusted Roots section, click Add.

    3. Click the Select trusted root(s) icon, select the public certificate of the CA that signed Identity Server certificates, then click OK.

    4. Specify an alias, then click OK > OK.

  3. To apply the changes, click Close, then click Update on the Access Gateways page.