![]() |
To avoid man-in-the-middle (MITM) attack, it is strongly recommended to enable Server Identity Validation when Experience Portal components use TLS connections to connect to external servers.
![]() | Note: |
Server Identity Validation is a global setting that applies to the entire Experience Portal system. It is a good approach to disable Server Identity Validation temporarily to avoid interruption of services. Services may get interrupted if some external servers still send valid certificates lacking valid Common Name or Subject Alternate Name. Contact the external servers vendors for correction of their certificates.
For Experience Portal to successfully validate an external server's identity, the identity certificates of the external servers must have the following attributes:
Valid Subject Common Name that represents the external server fully qualified hostname.
The X509 V3 Subject Alternate Name (SAN) extension must include valid DNS and IP Address entries associated with the external server domain name and actual IP address.
![]() | Note: |
|