|
Perle Systems Technical Note
Serial over SSL ( Secure Sockets Layer ) support on
IOLAN SDS, STS and SCS Terminal Servers
With SSL functionality, Perle enables organizations to securily connect
serial based legacy equipment across encrypted SSL/TSL sessions on private
or public networks such as internet.
Perle’s implementation of SSL goes beyond the simple encryption offered by
other vendors today. The IOLAN SDS, STS and SCS series provides multiple
cipher selection including AES and 3DES, key management, peer authentication
as well as the ability to operate in either SSL server or client modes making
it the best choice for all secure serial to Ethernet projects.
Secure Sockets Layer standardized by the IETF as TLS V1.0 ( Transport Layer
Security ), is a common method used to provide secure data exchange between
peers on a network such as the Internet. This technology is used today for
on-line banking to financial institution web sites using SSL enabled internet
browsers.
Available on the IOLAN SDS, STS and SCS series of device servers, users can
have sensitive serial data, such as credit card data on serial credit card
readers, passed across public or wireless networks to SSL enabled applications.
SSL sessions can be supported in the following configurations;
- Serial tunneling mode– Pass serial data between devices
- SSL Application to Device Server(s) – Pass TCP sockets from an SSL enabled
application to remote serial devices
- TruePort
Version 5 to Device Server(s) – Pass serial application
data from a host server with TruePort Version 5 to remote serial
devices attached to IOLAN SDS device servers
- Secure Vmodem – Pass encrypted Vmodem ( Virtual Modem ) traffic between
devices and a remote application that is designed to communicate with AT
command based modems
Perle’s TruePort
Version 5 used in conjunction with remote IOLAN SDS,
STS or SCS device servers can also be used to enable existing serial
applications to pass encrypted serial data across the network. TruePort
Version 5 with SSL is available on with the following O/S’s;
- Microsoft Windows 2003, XP and 2000
- Linux
- Solaris
- AIX
- SCO Unixware
- SCO Openserver
- HP UX
An extensive feature set is included with Perle’s implementation
of SSL;
- SSL V3.1 ( TLS V1.0 ) , SSL V3.0 and SSL V2.0 support
- Operate in either SSL Server or SSL Client mode
- Supported Encryption Ciphers : AES ( 256/192/128 ), 3DES, DES, RC4, RC2
- Configurable key lengths
- Hashing Algorithms: MD5, SHA-1
- X.509 Certificate Authentication: RSA, DSA
- Peer Validation Criteria: Country, State, Locality, Organization, Organization
Unit, Common Name, Email
- Certificate Authorities ( CA ) list with digital signatures from companies
such as Versign or self-signed certificates.
- Key Exchange: RSA, EDH-RSA, EDH-DSS, ADH
|