IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP

Documentation

Configure server security and database TLS

MSP Server administrator · Updated 9 October 2026

Follow the numbered steps, then check the result before continuing. Choose only the procedure that matches your task.

Before you begin

  • Install the MSP Server and identify the address clients will use. Use a stable DNS name where available.
  • For managed production certificates, obtain the correct server PFX/private key and public issuer chain from your administrator. High Assurance and DoD-Aligned also need individual client certificates.
  • Use Server Administration on the server. Keep a recovery copy and existing administrator access while testing changes.

1. Choose the profile and server certificate

  1. Open Guided security setup. Under 1.1 Select the protection level, choose the intended profile. Standard uses HTTPS; Enhanced adds managed trust/revocation and signed-request requirements; High Assurance and DoD-Aligned add stronger prerequisites including TLS 1.3 and mTLS. Read the on-screen profile explanation.
  2. Click 1.2 Use recommended settings for this level, then review the resulting choices. Selecting a profile prepares configuration; it does not prove the running listener has changed.
  3. Under 2.1, enter the real DNS name or IP clients will use, without https:// or a port. Example: audit.demodomain.com is a fictional placeholder; substitute your actual server address.
  4. Choose exactly one certificate method: 2.2a Choose certificate... for an installed certificate; 2.2b Import server PFX... for a certificate/private-key file; or 2.2c Create Standard lab certificate... for an intentional Standard lab setup. These buttons are alternatives, not three steps to perform in order.
  5. Click 2.3 Check address and certificate. Confirm that the certificate is valid, has its private key and Server Authentication usage, and that its SAN covers the entered name. An IP address requires an IP SAN; a matching Common Name alone is insufficient.
  6. Use 2.4 Export public server certificate... only when distributing the public certificate for reviewed trust setup. Never send the server PFX or private key to clients.
Check before continuingThe selected certificate passes the address/certificate check for the chosen profile. Resolve any error before applying security.

2. Prepare the managed local database connection

  1. In Guided security setup, click 3.1 Prepare managed database TLS.... Read the confirmation. This workflow is for the ITAF-owned local PostgreSQL instance, not an arbitrary third-party database.
  2. Confirm the operation only if the detected database is the intended managed instance. Wait for certificate preparation and the live VerifyFull connection test. The operation does not reset database passwords or configure network adapters.
  3. Read the status beneath the button. Continue only after the database TLS test passes. If the operation refuses unknown ownership or an existing custom certificate, use the administrator-configured database path below instead of replacing that certificate.
  4. For the ITAF-generated local database CA, note that it has no CRL/OCSP service and its setup explicitly disables database revocation for that chain. Do not confuse this setting with API certificate revocation. Enterprise revocation requirements need an enterprise-managed database certificate and CA.
Check before continuingThe application’s saved connection can authenticate the local database using VerifyFull. This does not establish TLS policy for every other PostgreSQL consumer.

3. Use a custom or remote PostgreSQL certificate

  1. Have the database administrator configure PostgreSQL TLS with its server PEM certificate, private key and issuer chain. The ITAF Database TLS & Recovery page tests/saves the app connection; it does not perform that server-side certificate installation.
  2. Open Database TLS & Recovery. In PostgreSQL DNS name / IP, enter the address matching that database certificate SAN. Do not copy the API server address unless it is also the correct database identity.
  3. Set SSL mode to VerifyFull. Use Select CA PEM... to select the public database CA file, or leave it blank only when the required issuer is correctly trusted through Windows.
  4. Set Check database certificate revocation according to the actual CA and deployment policy. If verification fails, investigate trust, name, expiry and revocation reachability instead of turning off checks to make the test pass.
  5. Click Test database TLS (read-only). After a successful live test, click Save verified database TLS. Open Server and click Restart when required to apply the saved connection.
Check before continuingThe test succeeds and the saved database settings use the intended host, CA and verification mode.

4. Apply the server profile and verify from a client

  1. Return to Guided security setup. Click 4.1 Review and apply security.... Review the address, port, certificate and profile before confirming the save/restart.
  2. Open Server and confirm the service returned to Running. If it did not, export the troubleshooting report and inspect the error before further changes.
  3. On an enrolled client, open Configuration → Security & Communications and click Verify Current Secure Connection. Confirm both the connection result and effective security level.
  4. If you used Security & Communications → Test Security Configuration on the server and saw PREFLIGHT PASSED (listener not yet verified), treat it as a configuration check only. Complete the save/restart and client verification above.
Check before continuingThe client confirms the intended effective security profile. DoD-Aligned is an application profile, not a certification or authorization.

If something goes wrong

SSL connection requested; no SSL enabled connection

The database connection is requesting TLS but PostgreSQL is not serving it for that connection. Use managed preparation or have the database administrator configure TLS, then retest.

AuthenticationException / SSL handshake failure

Check the exact failing layer: database TLS or client-to-server TLS. Review SAN, issuer chain, validity and revocation reachability. Export the corresponding diagnostic report.

PRELIGHT/PREFLIGHT passes but connection remains unverified

Apply the saved server settings, restart if requested, then run live verification from the client. Saved settings alone do not verify a listener.