Data required in the chapters
-
If available, a trust and/or keystore (if not, you will find explanations in the individual chapters)
-
The password for opening the key or trust store
General data
The following data is required for setting up OFTP2 communication:
-
Odette ID (SSID)
-
Password
-
Host name/IP address
-
Port (standard port without SSL: 3305)
Agreements
The following agreements must be made:
|
Settings or parameters |
possibilities |
|---|---|
|
Encrypt connection with SSL? |
*YES, *NO |
|
SSL client authentication? |
*YES, *NO |
|
OFTP authentication (secure authentication) |
*YES, *NO |
|
user data |
There are various ways to transfer user data. These can be defined as desired. |
|
Cipher suite |
*C01 - 3DES_EDE_CBC_3KEY RSA_PKCS1_15 SHA-1 *C02 - AES_256_CBC RSA_PKCS1_15 SHA-1 *C03 - 3DES_EDE_CBC_3KEY RSA_PKCS1_15 SHA-256 *C04 - AES_256_CBC RSA_PKCS1_15 SHA-256 *C05 - 3DES_EDE_CBC_3KEY RSA_PKCS1_15 SHA-512 *C06 - AES_256_CBC RSA_PKCS1_15 SHA-512 |
When do I need which data in my key/trust store?
|
Keystore |
Receive |
Send |
|---|---|---|
|
SSL |
|
|
|
My private key without client authentication |
X |
|
|
My private key with client authentication |
X |
X |
|
OFTP |
|
|
|
My private key with OFTP authentication |
X |
X |
|
My private key with file signing |
|
X |
|
My private key with file encryption |
X |
|
|
My private key for signed EERP |
|
X |
|
Truststore |
Receive |
Send |
|---|---|---|
|
SSL |
|
|
|
My private key without client authentication |
|
X |
|
My private key with client authentication |
X |
X |
|
OFTP |
|
|
|
My private key with OFTP authentication |
X |
X |
|
My private key with file signing |
X |
|
|
My private key with file encryption |
|
X |
|
My private key for signed EERP |
X |
|