Skip to end of metadata
Go to start of metadata


SSL stand for Secure Sockets Layer. It provides a secure connection between internet browsers and websites, allowing you to transmit private data online. Sites secured with SSL display a padlock in the browsers URL and possibly a green address bar if secured by EV Certificate.

Preparation

Under normal circumstances, the customer, or re-seller should have already installed the certificate in IIS.

Square 9 Support Engineers may perform this at their manager's discretion, but under normal circumstances, installing the cert should be the burden of either the Reseller or local IT.


Configuration

Adding SSL Certificate

In the event the client needs guidance on how to install an SSL Certificate, follow these instructions:

  1. Go into IIS (inetserv if launching from ‘run’)
  2. Select your Server name
  3. Click on ‘Server Certificates’
  4. Create a new Self-Signed Certificate and click OK
  5. Set and click OK
  6. Export the Self Signed Certificate (Optional, based on setup)

Please note: Errors installing the SSL Cert fall outside the purview and expertise of Square 9 Support and should be directed at local IT or at a Windows Technician

Adding and Removing Bindings from IIS

Bindings determine what port(s) users can access the website through. Since SSL/https runs on a different port than http, we're going to have to specify what port we're listening on for the external traffic.

  1. Right-click on your default website, or wherever SmartSearch is installed to
  2. Select ‘Edit bindings’
  3. Click ‘Add’
  4. Select Type: Https, SSL Certificate:, and the click OK
  5. (Optional) If your client wants to completely disable authentication over http (locally) remove http bindings (usually port 80). If client wants to let users authenticate from within the domain, you can keep your http bindings without issue.

SSL Settings

  1. click on your Default Website in IIS again
  2. Select ‘SSL Settings’
  3. Click on Require SSL to enable it, and the select ‘Ignore’ for client certification
  4. Apply the changes

At this point, IIS should be correctly configured for SSL. The remaining portions of the configuration will have to do with modifying configuration files to use the new address and port.

Web.config SSL Configuration Changes

Square9REST web.config

  • Un-comment the section below (if you are unable to find these lines, you can do a ctrl+f to find it):
<!--For SSL enable this section.-->
<!--
<binding>
<security mode="Transport" />
</binding>
-->


In versions prior to 4.2, you will also need to uncomment this section:


<!--For SSL enable this section.-->
<!-- 
<security mode="Transport" > 
<transport clientCredentialType="Windows"/> 
</security> 
-->


Please Note: In Version 4.2 and below, you will need to change clientCredentialType to “InheritFromHost“.


Change this line:

 http://localhost/getsmart/folders.asmx
     
     To:
     
 https://localhost/getsmart/folders.asmx

Address Changes Across All Configuration Files

  1. Change all of the Program Configuration files to use ‘https’ instead of ‘http‘ and change the IP, or server name to the FQDN (Fully Qualified Domain Name. ex Fullyqualified.domain.name.com) This includes switching any references to 'Localhost' in the config files to use the FQDN.
  2. Configuration Files to Change: 
    1. All Configuration files in your Server Getsmart directory, including your RestProxy.xml file
    2. All Configuration files in your Client Install Directory, including your RestProxy.xml file
    3. All Configuration files in your inetpub\wwwroot\getsmart\upgrades directory, including your RestProxy.xml file
    4. Your Engine configuration file in Capture Services\GlobalCapture_#\ Directory (4.4+)
    5. The web configs located in the following virtual directories:
      1. Getsmart
      2. Square9API
      3. Square9CaptureAPI (4.4+)
      4. Square9Rest
      5. Square9Viewer
  3. Here is a URL to test your configuration
https://INSERTYOURFQDN:443/Documents/db

If you are prompted to log in after this is done, you have correctly configured your SSL address for external use.