Connection Hosting Center Access Instructions_Final.doc
DOC document 904 KB Posted
- Attached to
- Connections II Solicitation Federal contract opportunity
- Solicitation number
- QTA010ABA0023
- Issued by
- GSA Federal Acquisition Service
About this file
Connection Hosting Center Access Instructions
View the file
Other files for this federal contract opportunity
Show all 50
Connections II Solicitation has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Connections II Hosting Center Access Instructions
Connections II Hosting Center Access Instructions
May, 2010 Executive Summary
The Connections II Hosting Center provides electronic access through a secure internet website to information that must be accessed as part of the Connections II solicitation. This information includes pricing tables and compliance matrices. The pricing tables mirror the pricing tables contained in Section B of this solicitation. Detailed pricing instructions including pricing descriptions, charging units, and Contract Line Item Number (CLIN) identifications are also contained in Section B.
Vendors develop prices per the technical requirements in Section C and the pricing instructions in Section B and populate the pricing (or CLIN) tables for the Connections II equipment and services. These completed tables are the basis of the Vendor’s price proposal. The Connections II Hosting Center will error check submissions, and provide the information to Vendors on detailed reports.
General Instructions
This document provides instructions to the user in how to set up the IPSEC VPN connection and access the Connections II Hosting Center. The companion to this document, “Connections II Hosting Center User Instructions.doc”, which will be available with the release of the Request for Proposals (RFP), contains instructions on how to use the Connections II Hosting Center for submitting proposal and pricing data.
This instruction set is intended to aid the average computer user to configure an IPSEC VPN connection between his/her Microsoft Windows computer and the remote provider. It is recommended that the instructions be read in their entirety prior to beginning an implementation. The process requires no specialized knowledge but each step in the process is very important, so please read carefully. For ease of use, all certificate-related files should be stored in a common folder, C:\Certs.
Note: Users should create this folder (‘C:\Certs’) on their computer prior to starting the process of configuring the VPN connection.
The first section of this document provides instructions on purchasing a signed certificate from a trusted Certificate Authority. The second section provides instructions generating a private key and Certificate Signing Request (CSR). This CSR will be used in the third section to obtain a signed certificate from a trusted Certificate Authority. The private key is unique to the workstation on which the certificate is installed and should be properly protected. An easy-to-use open source application can be used to generate these files (a link is provided), although the certutil.exe from Microsoft Corporation could also be used. The user should utilize whatever tool the user is most comfortable with.
The third section requires the user to interact with an ACES Certificate Authority (CA), through the CA’s website. The user will submit the CSR to the CA and the CA will then return the signed certificate to the user. The signed certificate will allow the user to connect to the Connections II Hosting Center while ensuring the identity of the user. The issuance of a signed certificate is a process where trust is important, so the CA is charged with due diligence in verifying the user’s identity; it may take several days before the user receives the signed certificate.
Once the signed certificate is received, the user is instructed in section 4 on how to submit the application forms with this signed certificate to the General Services Administration (GSA). Next, the user receives a Connections II Hosting Center CD with the VPN Helper utility and other files and must follow the instructions in section 5 to setup the VPN. Lastly, the user tests to ensure they have proper connectivity to the Connections II Hosting Center.
Once the IPSEC settings are in place the user can verify connectivity by connecting to the remote server via a web browser. This verifies the connection is working.
Once connected, the user will be able to access the price tables and input pricing data and other proposal volume information. See the companion document, “Connections II Hosting Center User Instructions.doc”, for detailed instructions, when available.
Prerequisites The following instructions were developed on Windows XP Service Pack 3, although they should be applicable to most modern versions of Microsoft Windows including Windows XP SP2. Operating systems prior to Windows XP or Windows 2003 server are not supported.
The user must have a static IP Address. If the machine used to connect to the Connections II Hosting Center has an IP address that is behind a Network Address Translation (NAT) router/firewall, then the operating system of the machine must be Windows XP or Windows 2003 Server. Vista, Windows 7, and Windows Server 2008 do not work with NAT over IPSEC tunnels.
Browser requirements:
Internet Explorer 8.0 or Firefox 3.5 at a minimum
Step 1. Purchase a Signed Certificate from a Vendor.
The user must purchase a signed certificate from either Identrust or ORC.
If using IdenTrust:
To purchase a VPN IPSEC certificate from Identrust, go to the following URL to start the process:
http://www.identrust.com/certificates/index.html Click on the BUY button for the VPN IPSEC Client, and follow the Identrust instructions.
If using ORC:
To purchase a certificate from ORC, go to the following URL to start the process:
http://aces.orc.com/busRepVPNOblig.html
In the case of buying a certificate from ORC, the CSR must be generated and included in the application process for ORC. In addition, the Hostname and IP Address of the machine establishing the VPN connection to the Connections II Hosting Center must be submitted. See your system administrator to obtain your hostname and IP Address. See Step 2 for generating a CSR.
Step 2. Creating a CSR and Private Key
Prior to requesting a signed certificate from a trusted Certificate Authority (CA) you will need to generate a private key and matching Certificate Signing Request (CSR). In order to do this, the user may use the open source application MyCert.
If MyCert is used to generate the CSR and Private Key, then the following steps must be followed:
1.Download the following 3 files and save them into the C:\Certs directory
a. www.nan.noblis.org/software/mycert.exe
b. www.nan.noblis.org/software/mycert.ini
c. www.nan.noblis.org/software/libeay32.zip
2. Unzip or extract the file libeay32.dll from the zip file into the C:\Certs folder.
3. Double click on “mycert.exe”.
The following screen will appear:
Fill in the fields. Choose a pass phrase that you can remember, or else write it down in a safe place. Change the folder to C:\Certs, by clicking on the Change button. When all fields are completed, click the CREATE REQUEST button.
The application generates a private key for the users use (stored as a .key file in the C:\Certs folder) and the request (stored as a .req file in the C:\Certs folder). Additionally, the user must copy/paste the request information presented in the next dialog:
Save the text into a file called: certreq.txt in the C:\Certs directory.
Follow the chosen CA’s instructions for submitting the CSR, normally done via a web interface. Step 3 provides the instructions for submitting the CSR. Use the certreq.txt file when submitting the CSR.
The user must have the private key available when they receive the signed certificate, as it is uniquely tied to the certificate they will receive. They must keep the private key secured to maintain the security of this mechanism. Do not transmit this key in an unsecured fashion (such as email or ftp). Additionally the user must have the pass phrase used to generate the key and request. Failure to retain these two items will make completion of this task impossible.
Step 3. Obtaining a Signed Certificate.
If using Identrust:
Use a web browser to connect to the Identrust Certificate Authority website (https://secure.digsigtrust.com/tsapp/bus-start.jsp?AT=216&CT=530008) and follow a wizard-driven process to submit the users CSR. Once completed, it may take several days before the signed certificate is available to the user. In the meantime, the user will also need to download the CAs root certificate. This is normally available under the SUPPORT option of your CAs website, although some will also provide this as part of retrieving your signed certificate.
Once the user has received their signed certificate they will have the components needed to authenticate to the IPSEC VPN.
Note the filename provided when the user saves the signed certificate (the example server.txt will be used in the following section). Please save all files (the signed certificate and all root CA certificates) to C:\Certs. Note, in Step 5, this file is called the Public Key.
If using ORC:
For ORC please follow the detailed instructions on the following websites.
Instructions - http://aces.orc.com/instructions.html Aces IP Sec - http://aces.orc.com Help Desk - http://aces.orc.com/help.html Step 4. Submitting Your Application Forms There are 5 application forms that must be submitted to the Connections II Contracting Officer (see associated files).
1. Agreement to Restrict Access to certain Connections II Hosting Center Information
2. List of Designated Users
3. List of IP Addresses and Certificates
4. CD with copy of the certificate file(s) issued by ACES Certification Authority
5. Vendor Application
The CD containing the certificate file(s) must contain the certificate(s) obtained in Step 3, known as the Public Key.
The List of IP Addresses can be obtained as follows:
1) Obtain the Local IP Address of the machine that will be used to connect to the Connections II Hosting Center.
a) Click the start button in the lower left corner of the screen.
b) Click “Run”.
c) Type “cmd” and then click “ok”.
d) When the new window opens up, type “ipconfig” at the command prompt.
e) Press enter.
f) The user will then see their IP Address. It will be different depending on the user’s location. Thus, this access can only be utilized by a single device at a single location. Use this IP Address when filling out the IP Address field on the form.
2) If you are behind Network Address Translation (NAT), obtain the Public Visible Static IP Address – should be obtainable from your IT department. Note - This must be the “final” IP address sent by the server. Using the command : ping www.xxx.com does not give the correct IP.
Step 5. Using the VPN Helper Utility Once the application forms have been received and accepted by the Connections II Contracting Officer, a “VPN Helper CD” will be mailed to the user to complete the Connections II Hosting Center Access process.
The CD will contain the following files:
1) Setup conn2-VPN.bat (for running the VPN helper utility)
2) Connections II Hosting Center User Instructions.doc
3) psqlodbc.msi (an ODBC Driver)
4) readme.txt – which will contain
a) Connections II Hosting Center Help Desk Phone #
b) Vendor Number and PIN (to be used when calling the help desk)
c) Usernames and passwords based on the usernames supplied on the application form
d) IP address of the Connections II Hosting Center for web-browsing and ODBC access
When you receive the VPN Helper CD, insert the VPN Helper CD into the computer.
Double click on “Setup conn2-VPN.bat”.
The 1st field titled “Public Key” should be pre-populated with the user’s public key.
On the second field titled “Private Key”, click on the box to the right and browse to the location (C:\Certs) where the key is stored.
Lastly, enter the user’s private key password. At this point the user clicks the box marked “Setup VPN”. The VPN Helper configures the computer and prompts the user to go to the Connections II Hosting Center.
Step 6. Completion and Testing
You will now have access to the Connections II Hosting Center website. You have successfully completed setting up your connection. For testing purposes, you can navigate to that IP address via a web browser. Enter the IP Address provided in the readme.txt file on the CD into your web-browser.
- 13 -
File details come from the government source that posted it. Updated .