Chapter 4 | Section 4.3 |
Operating SSL | SSL Handshaking |
Figure 9 Server-side Authentication
Client | Handshake: Client Hello | Server |
(eWay) |
| (Web |
|
| Server) |
| Handshake: ServerHello |
|
Handshake: Certificate
Handshake: ServerHelloDone
Handshake: ClientKeyExchange
ChangeCipherSpec
Handshake: Finished
ChangeCipherSpec
Handshake: Finished
Dual authentication: This option requires authentication from both the eWay and Web server. The server side (Web server) of the authentication process is the same as that described previously. In addition, however, the Web server requests a certificate from the eWay. The eWay then sends its certificate to the Web server. The
server, in turn, authenticates the eWay by looking into its TrustStore for a matching trusted CA certificate. The communication channel is established by the process of both parties’ requesting certificate information. This option is illustrated in Figure 10.
HTTPS eWay Adapter User’s Guide | 34 | Sun Microsystems, Inc. |