BlueZone Security

Chapter 8

Secure Sockets Layer

BlueZone provides additional security features beyond those supplied through the network operating systems (NOS) or the native host security systems.  The primary security function is a full implementation of the Secure Sockets Layer (SSL / TLS) protocol that provides privacy, authentication, and message integrity.  When used in conjunction with the BlueZone Security Server, BlueZone provides RSA SecurID Authentication and NT Domain Authentication.  The iSeries also provides password encryption through the TN5250E server, referred to as the Encrypted Substitute Password feature, which BlueZone also supports.

Secure Sockets Layer is the current Internet standard to insure privacy, message integrity, and authentication.  This standardization ensures that BlueZone emulation clients will work with any SSL enabled telnet server including OS/390, IBM CSNT, Novell NWSAA, and OS/400.  If an SSL enabled telnet server is not available, the Security Server can SSL enable any telnet server.

SEE  SSL Configuration for the telnet server being used for additional information.  If the Security Server is being used, see the BlueZone Security Server Administrator's Guide for more information.

The SSL feature may be implemented in BlueZone on a connection-by-connection basis during the configuration process.  BlueZone may also be distributed pre-configured with the SSL settings, eliminating user intervention in the installation and configuration process.

SEE  BlueZone Display & Printer Help for more information about configuring the Secure Sockets Layer feature in the Session Configuration.

TIP  All BlueZone documentation can be found on the BlueZone CD-ROM or BlueZone CD image.  To locate a particular document, double click the DocumentationRoadmap.htm document located in the root of the BlueZone CD-ROM or BlueZone CD image.