ace00002.gif Ensuring That Every Connection is Secure


If you do not have a Secure Sockets Layer (SSL) certificate installed on your Web server, you are leaving protected pages open to replay attacks. An unauthorized person can monitor an unsecured connection, intercept a tokenholder’s PASSCODE or cookie, and then use the stolen object to access protected pages.

Security Dynamics strongly recommends that you install an SSL certificate, but if you wish to bypass this security measure, leave the Require secure connections to access protected pages checkbox unmarked in the ACE/Agent Administration applet.

For more information about how to obtain an SSL site certificate from a Certificate Authority, visit the VeriSign Corporation's Web site.


To require all tokenholders to use SSL connections:

  1. Open the ACE/Agent Administration applet.
       
  2. In the “Connection security” group, mark the Require secure connection to access protected pages checkbox.
       
  3. Click Apply.

Preventing tokenholders from caching protected pages