Using TLS with AFP Download Plus
Use this procedure to configure TLS settings that enable encrypted communication with AFP Download Plus. The settings generate a configuration file that Download input devices use to establish secure connections.
Before you start, verify these items:
- You have Administrator access to RICOH ProcessDirector.
- The server or servers that you plan to use as parent servers for the Download input
devices used with AFP Download Plus.
In a basic environment, the primary server is the parent server for all input devices. However, if you have secondary servers or run a multiple primary configuration, you can set any of those servers as the parent server.
- You have the required certificate files:
- An unencrypted PEM certificate file
- A certificate private key file
- If using mutual authentication, a certificate authority (CA) file
- Optional: a certificate revocation list (CRL) file
If you run a multiple primary environment or plan to use a secondary server as the parent server for your Download input devices, get certificates for each server.
- (Windows) The certificate files are accessible from the RICOH ProcessDirector primary server.
- (Linux) The certificate files are stored on the servers that use them.
Store the files with the same names and in the same location on each server, as RICOH ProcessDirector can only store one value for the full path to each file.
To use TLS with AFP Download Plus:
- Click the Administration tab.
- Click .
- In the Certificate file field, enter the full path to the unencrypted PEM certificate file.
- In the Certificate private key file field, enter the full path to the certificate private key file.If the server certificate file and certificate private key file are combined into one file, this field should be left blank.
- Optional: To require mutual authentication, under Mutual Authentication select Enable.When you enable mutual authentication, both the RICOH ProcessDirector server and AFP Download Plus client must present valid certificates. Additional configuration options become available.
- In the Certificate authority file field, enter the full path to the CA file.This file is required when mutual authentication is enabled and the client certificate is not signed by a globally known CA.
- In the Certificate revocation list file field, enter the full path to the CRL file.
- Choose settings for Ignore certificate errors and Ignore hostname errors in accordance with your security procedures.
- In the Certificate authority file field, enter the full path to the CA file.
- Click Save.RICOH ProcessDirector validates that the specified files exist and saves the TLS configuration.
- Update your Download input devices to use the TLS configuration:
- Click the Administration tab.
- Click .
- Right-click the Download input device you use and select Properties.
- On the General tab, set Use secure TLS to Yes.
- Click OK.
The TLS settings are saved to the configuration file at $AIWDATA/config/msdownload-tls.cfg. The updated Download input devices use this file to establish secure connections
with AFP Download Plus.