Laserfiche WebLink
)� TRITF--CH <br />SOFTWARE SYSTEMS <br />Inform RIMS System Planning Document <br />Virtualized Desktop clients are not required for Inform RMS. <br />Inform RMS will require a web certificate. This is a template type issued from a certificate <br />authority. If the client is hosting Inform RMS on premise then they can use a private CA <br />(Certificate Authority) server in-house to generate the certificate. This server must be an <br />enterprise CA, meaning that it is a CA that has been added to the clients domain by a domain <br />admin and has access to the AD directory (to which it references the template directory <br />managed by AD). <br />This cent will serve two purposes first it is bound to the IIS server to provide https transmission. <br />For this reason the certificate common name (CN) must match the domain name of the IIS <br />server <machinename>.domainname.local or <domainaddress>.com <br />The second purpose of this certificate is to manage the encryption and decryption of the <br />handshake between the security tier and the application. This portion only compares <br />thumbprints of the cert so the CN is not relevant. For convenience of certificate management we <br />use the same cert but you could use two separate certificates if so desired. <br />You will need a certificate issued for each instance of IIS (which would be a unique domain <br />name). There are a couple of variables. If each tier needs to be accessible via IIS and have an <br />external domain name then you will need a certificate bound to each IIS server which would <br />require the issuance of a certificate to each server. If you are stacking all tiers on one server <br />then you only need one cert. There are multiple scenarios depending upon the requirements of <br />implementation. An example would be you have the three tiers mentioned and SSL is only <br />required for the client which is the access point. You will want to always stack the client and <br />security tier together whereas app could be separate. In this example you would generate a cent <br />for the SSL binding for the client and security tier, this cert could then be installed on all tiers <br />and used for the handshake (but not applied to the ssl binding for the app tier if it is not needed). <br />If the client is hosting Inform RMS externally on an external web address then the certificate <br />must be issued by a public CA (Digicert, Verisign, GoDaddy etc). The same rules apply here <br />only that it must be issued from a public CA. <br />For public CA's some clients may want to use a wildcard cert. While not recommended (for <br />security reasons) this is acceptable. The rule here is that the wildcard must adhere to the <br />Page 13 of 25 <br />Proprietary Information. Do not duplicate or disclose. <br />TriTech Software Systems Proprietary Copyright02015 <br />