Previous Topic: Creating and Managing Security CertificatesNext Topic: Securing CA Configuration Automation UI Access


Securing CA Configuration Automation Server to CA Configuration Automation Agent Communications

There are two communications channels between the CA Configuration Automation Server and the CA Configuration Automation Agent:

The only communications initiated from the agent are those that allow for the automatic registration of an agent with the CA Configuration Automation Server and those that periodically send the server basic agent configuration and server information. This feature is optional and is not required for the successful operation of CA Configuration Automation. No secure mode is provided for agent to server communications. In a secure environment, you can disable the Server Ping option.

All other communications between the server and an agent (including discovery and refresh operations) are initiated from the server. Securing these communications protects the data exchanged between the managed servers and the CA Configuration Automation Server through encryption, and prevents unauthorized access to agents through authentication. The security cipher suite uses RSA key exchange, the RC4 stream cipher with 128-bit keys, and MD5 digests over TLS v1.