Print

Best practices for Server Identity Validation

1. Enable Server Identity Validation

To avoid man-in-the-middle (MITM) attack, it is strongly recommended to enable Server Identity Validation when Experience Portal components use TLS connections to connect to external servers.

noteNote:

Server Identity Validation is a global setting that applies to the entire Experience Portal system. It is a good approach to disable Server Identity Validation temporarily to avoid interruption of services. Services may get interrupted if some external servers still send valid certificates lacking valid Common Name or Subject Alternate Name. Contact the external servers vendors for correction of their certificates.

2. Identity certificate requirement of external servers

For Experience Portal to successfully validate an external server's identity, the identity certificates of the external servers must have the following attributes: