Blog

Managed File Transfer and Network Solutions

Setting Up Client Certificate Authentication On An AS2 Server

Posted by John Carl Villanueva on Sun, Dec 13, 2015 @ 06:18 AM

Overview

Not all AS2 servers authenticate trading partner clients through usernames and passwords. Many use digital certificates. If you want to know how to set up this kind of authentication on your AS2 server, read this post. 


 

This tutorial involves two AS2 servers. The first AS2 server acts as the "sender" and the second AS2 server acts as the "recipient". Let's call the first server AS2 Server 1 and the second, AS2 Server 2.

AS2 Server 1 can also be considered the "client" and AS2 Server 2 the "server" in a client-server architecture. In order for the server to authenticate the client, the server must possess the public key that corresponds to the client's private key.  

 

as2_digital_certificate_authentication.png

 

All steps and screenshots shown below are based on the JSCAPE MFT Server environment. JSCAPE MFT Server is a managed file transfer server that readily supports AS2 transactions. You may download a free, fully-functional evaluation edition of this AS2 server by clicking this download button:

 

Download Now

 

Before we proceed, you need to set up the two AS2 servers. Setting up an AS2 service on JSCAPE MFT Server is easy. Just follow the instructions in the tutorial

The Quickstart Guide To Setting Up An AS2 Server

Do that for the two AS2 servers. Ready with your AS2 servers? Let's proceed. 

 

Creating the private key and its corresponding digital certificate 

Note: This is done on AS2 Server 1

The first steps are going to be carried out on AS2 Server 1 (a.k.a. the client). That's where we'll generate a private key and a digital certificate. The digital certificate will contain the private key's corresponding public key. Once this certificate (along with the public key) is imported into AS2 Server 2 and the private key loaded unto the AS2 Server 1 side, the two parties will then be ready to perform certificate-based authentication. 

We already wrote a tutorial for creating a private key and its corresponding certificate. Just follow the steps in the article How To Create A Client Certificate until you reach Step 4. Instead of exporting the private key in PKCS12 format, export it in JKS. 

The reason is that we'll be loading our private key unto a JSCAPE MFT Server "Trading Partner" object, which currently only supports JKS. Don't forget to assign a key filename and a corresponding password. 

 

export_private_key_jks.png

 

Save the private key file and store it in a secret location.  

 

save_jks_private_key_file.png

 

Now that you've created the private key, you'll now need to export that private key's public key. Again, the public key will have to be stored in a digital certificate. To export the digital certificate,

1. Go back to the Client Keys tab,

2. Select the newly generated client key,

3. Click Export and then

4. Click Certificate

 

export_client_certificate_for_as2.png

 

As soon as the Export Certificate dialog appears, specify a file name (or keep the one generated for you) and then select a certificate format. You'll usually want it to be in X.509. Click OK.

 

export_client_certificate_for_as2_x509.png

 

A certificate file will then be automatically generated. Save that file. You should now import this file into AS2 Server 2. In a real world scenario, you will have to send this certificate out-of-band to your trading partner's server administrator. That person will then have to import the file you sent into his AS2 server. 

 

saving_exported_client_certificate_crt_file.png

 

Importing certificate into the authenticating server

Note: This is done on AS2 Server 2

We'll now import that digital certificate into the authenticating server, which in our case would be AS2 Server 2. AS2 Server 2 will use this certificate to authenticate AS2 Server 1 when the latter first attempts a connection. 

To import the certificate, go to Server > Settings > Client Keys tab, and then click the Import button. 

 

import_client_certificate_for_as2_authentication.png

 

Give the public key / certificate an alias. An alias is just an arbitrary name that will be used to represent this particular key in this server's environment. 

After that, click the Browse button and then navigate to the digital certificate file. Click OK to proceed with the import process.  

 

import_client_certificate_crt_file_for_as2_authentication.png

 

If the import succeeds, you should see the alias of your newly imported certificate under the Certificates node of your Client Keys tab.

 

newly_imported_client_certificate_for_as2_authentication.png

 

Enabling HTTPS client certificate authentication

Note: This is still done on AS2 Server 2

In case you didn't know, AS2 runs on HTTP/S. AS2 servers are actually able to perform certificate-based authentication because that capability already comes with HTTPS. Thus, for all this to work, you need to make sure HTTPS is already enabled and that the server is set to require HTTPS client certificates. 

To set up HTTPS, read the post:

How To Set Up A HTTPS File Transfer

To require client certificates, go to Server > Settings > Web > Web tab and then tick the HTTPS client certificate required checkbox. 

 

https_client_certification_required_for_as2.png

 

We're now done on the "server" side. It's time to go back to the "client" side. 

 

Loading up the private key unto the AS2 Trading Partner object

Note: This is done on AS2 Server 1

Now that the public key certificate has already been imported on the authenticating server's side, it's time to load our private key unto the client. In this case, the client will be a Trading Partner object on JSCAPE MFT Server. 

If you followed the instructions in The Quickstart Guide To Setting Up An AS2 Server, as instructed earlier in this article, you should now have a Trading Partner object ready for use. Edit that trading partner and click the Client Key button. 

 

as2_trading_partner_settings_client_key.png

 

When the Client Key dialog pops up, select the Use key file option and then browse to the location of the private key file. Select the key file and enter its corresponding password. 

 

select_client_key_for_as2_authentication.png

 

As soon as you click OK, you will have already completed the steps for setting up certificate-based authentication for your AS2 server. 

Confused? Leave a comment below or on any of our social media accounts.  

 

You might also want to read

What Is Client Certificate Authentication?

How To Set Up An Automated AS2 File Transfer

What is EDI X12?

AS2 Simplified

 

Topics: JSCAPE MFT Server, Managed File Transfer, Business Process Automation, AS2