11.3.2 Peer Node Configuration
Perform the following procedure to enable DESS (Diameter End-to-End Security)
in the peer node:
Note:
The DESS feature is disabled by default.- Log in to the active SOAM (Service Operations, Administration, and Maintenance) GUI.
- From the Main Menu, navigate to Diameter, Configuration, Peer Nodes, and then click Insert.
- Select the Enable DESS Feature check box.
- Upload the CA CERT.
- Upload the Public Certificate.
Note:
Certificates must be in .pem format. - Select a DESS algorithm from the dropdown menu:
- RSA_SHA_256
- EC_DSA_SHA_256
- DSA_SHA_256
- If signature verification fails for the peer node, select one of the
following options from the Action on Verification Failure
dropdown menu:
- "Send Error": The DSR returns a Diameter answer message with result code 5012: UNABLE_TO_COMPLY.
- "Silently Discard Error": The system discards the received message without any further action.
- Click Apply.
.
Note:
Upon applying, the GUI verifies the certificates and displays an error if the public certificate is not issued by the CA certificate or if the public and private certificate do not match.Figure 11-5 Peer Node Configuration
