Advanced Configurations for Secure Communication with HTTPS

Overview

Support for secure communication with HTTPS is available in some of the Oracle E-Business Suite 10.x mobile apps for certificates from commercial Certificate Authority (CA) vendors, as well as custom or self-signed certificates.

To enable TLS in Oracle E-Business Suite mobile apps, ensure that you complete the following tasks for your app:

Note: The information described in this chapter does not apply to Oracle Mobile SCM for EBS (MSCA) and Oracle Field Service for EBS.

For information on configuring TLS port and adding custom certificates to Oracle Mobile SCM for EBS, see Document 2108155.1, Oracle Mobile Supply Chain Applications for Oracle E-Business Suite Release Notes.

Setup Tasks for Oracle Approvals for EBS, Oracle Timecards for EBS, and Oracle Self-Service HR for EBS

Perform the following tasks to enable TLS for your app:

  1. Setup Tasks for Enabling TLS in Oracle E-Business Suite

  2. Mobile Specific Setup Tasks for TLS Connections

Step 1: Setup Tasks for Enabling TLS in Oracle E-Business Suite

The setup tasks described in this section are common tasks for enabling TLS in Oracle E-Business Suite. These tasks serve as prerequisites for configuring Oracle E-Business Suite mobile apps for TLS connections. Oracle E-Business Suite mobile 10.x apps support TLS 1.2 only and TLS 1.2 with backward compatibility (recommended). Before performing setup tasks for mobile apps, ensure your Oracle E-Business Suite environment is TLS enabled.

For information on enabling TLS 1.2 only and TLS 1.2 with backward compatibility in Oracle E-Business Suite, see My Oracle Support Knowledge Document 1367293.1, Enabling TLS in Oracle E-Business Suite Release 12.2.

Step 2: Mobile Specific Setup Tasks for TLS Connections

Once your Oracle E-Business Suite is TLS enabled, perform the following additional app-specific setup task to ensure successful TLS connections for your app.

Using Custom or Self-signed Certificates with Oracle E-Business Suite Mobile Apps

For Oracle Approvals for EBS, Oracle Timecards for EBS, and Oracle Self-Service HR for EBS, mobile users of these three apps can dynamically add custom CA or self-signed server certificates to the apps accessible through web page URLs for TLS connections to Oracle E-Business Suite.

Importing Certificates Dynamically for Oracle Approvals for EBS, Oracle Timecards for EBS, and Oracle Self-Service HR for EBS

Perform the following steps to import certificates after accessing the app through a web page URL:

  1. Save the custom CA or self-signed certificate file in binary format (DER), for example, <ca-cert-filename>.cer.

    Note: Use keytool or an appropriate tool to view the contents of the certificate file <ca-cert-filename>.cer and confirm that the file is the correct self-signed or custom CA certificate for the Oracle E-Business Suite environment. If the correct certificate for the Oracle E-Business Suite environment is not imported to the app, then the app user cannot connect to the Oracle E-Business Suite server.

  2. Change the extension of the certificate file to <ca-cert-filename>.servercert.

  3. Upload the certificate file to an internal server where your mobile users can access from their mobile devices.

  4. Ask your mobile users to access your desired Oracle E-Business Suite mobile apps.

  5. Open the certificate file from the internal server using the mobile device's web browser.

    • For iOS devices, use Safari web browser to open the certificate file.

    • For Android devices, use Chrome web browser to open the certificate file.

  6. When prompted, select the Oracle E-Business Suite mobile app to open the certificate file with so that it is imported into that app.

  7. Restart the app and connect to Oracle E-Business Suite.

  8. Repeat the tasks from step 5 to step 7 for each Oracle E-Business Suite mobile app that should connect to that server.

Setup Tasks for Oracle Maintenance for EBS

Oracle Maintenance for EBS supports TLS connection only when your Oracle E-Business Suite server certificates are public or commercial-CA issued TLS certificates. There is no app-specific setup task required for this app.

Note: In this Release 10.x, Oracle Maintenance for EBS does not support custom or self-signed certificates.

The only setup task is to ensure that your Oracle E-Business Suite environment is TLS enabled. See: Setup Tasks for Enabling TLS in Oracle E-Business Suite.

Important: Before setting up your mobile app with any of the advanced configurations, ensure basic mobile app configuration is performed and validated. See: Validating the Configuration.

Setup Tasks for Enabling TLS in Oracle E-Business Suite

This task is to ensure that your Oracle E-Business Suite environment is TLS enabled.

Note that Oracle E-Business Suite mobile 10.x apps support TLS 1.2 only and TLS 1.2 with backward compatibility (recommended).

For information on enabling TLS 1.2 only and TLS 1.2 with backward compatibility in Oracle E-Business Suite, see My Oracle Support Knowledge Document 1367293.1, Enabling TLS in Oracle E-Business Suite Release 12.2.

No App-Specific Setup Tasks

Once your Oracle E-Business Suite is TLS enabled, you can have TLS connection as long as the server uses public or commercial-CA issued TLS certificates. There is no additional setup task for Oracle Maintenance for EBS.