-  
                     				ESCWA 
                     			 
                  
-  
                     				
                     To ensure the 
                        				  ESCWA network endpoint will honor the server cipher list, use 
                        				  ESCWA to perform the following steps: 
                        				
                       
                        				  
                        -  Click 
                           					   This opens the 
                              						Enterprise Server Administration Configuration dialog box. 
                              					 
                            
- Expand 
                           					 Server Settings 
                           				  
                        
- Click 
                           					 TLS Settings. 
                           				  
                        
- Expand 
                           					 Advanced. 
                           				  
                        
- Check 
                           					 Honor Server Cipher List 
                           				  
                        
- Click 
                           					 Apply. 
                           				  
                        
- Restart the 
                           					 ESCWA process. 
                           				  
                        
 
-  Directory Server 
                     			 
                  
-  
                     				
                      To ensure a Directory Server network endpoint will honor the server cipher list, use 
                        				  ESCWA to perform the following steps: 
                        				
                       
                        				  
                        - In the top menu bar, click 
                           					 Native. 
                           				  
                        
- In the 
                           					 Native Navigation pane, expand 
                           					 Directory Server. 
                           				  
                        
- Click the directory server you require, then click 
                           					 . 
                           					 
                           This takes you to the 
                              						Connections Properties page. 
                              					 
                            
- Check 
                           					 Enable TLS. 
                           				  
                        
- Check 
                           					 Use Custom Certificates. 
                           				  
                        
- Expand 
                           					 Advanced. 
                           				  
                        
-  Check 
                           					 Honor Server Cipher List. 
                           				  
                        
- Click 
                           					 Apply. 
                           				  
                        
-  Restart the Directory Server process. 
                           				  
                        
 
-  Communications Process 
                     			 
                  
-  
                     				
                      To ensure a 
                        				  region's Communications Process' network endpoint will honor the server cipher list, use 
                        				  ESCWA to perform the following steps: 
                        				
                       
                        				  
                        - In the top menu bar, click 
                           					 Native. 
                           				  
                        
- In the 
                           					 Native Navigation pane, expand 
                           					 Directory Server. 
                           				  
                        
- Click the 
                           					 region you require. 
                           				  
                        
- Click 
                           					 . 
                           					 
                           This opens the 
                              						Communications Server Properties page. 
                              					 
                            
- In the 
                           					 Native Listener Navigation pane, click the 
                           					 Communications Process you require. 
                           				  
                        
- Expand 
                           					 Configure. 
                           				  
                        
- Click 
                           					 TLS Settings. 
                           				  
                        
- Check 
                           					 Enable TLS. 
                           				  
                        
- In the 
                           					 Certificate File field, type the location of the TLS certificate on the machine where this region runs. 
                           				  
                        
- In the 
                           					 Keyfile field, type the location of the TLS key on the machine where this region runs. 
                           				  
                        
- In the 
                           					 Server CA Root Certificate File field, type the location of the server CA root certificate on the machine where this region runs. 
                           				  
                        
- Expand 
                           					 Advanced. 
                           				  
                        
- Check 
                           					 Honor Server Cipher List. 
                           				  
                        
- Click 
                           					 Apply. 
                           				  
                        
- Restart the 
                           					 region so the changes are applied. 
                           				  
                        
 See 
                        				  To Configure the Passphrase in a File for more information on setting the keyfile passphrase. 
                        				
                      Next time the 
                        				  region is started, the network endpoint will be TLS enabled. 
                        				
                      
-  Listener 
                     			 
                  
-  
                     				
                      To ensure a 
                        				  region's listener's network endpoint will honor the server cipher list, use 
                        				  ESCWA to perform the following steps: 
                        				
                       
                        				  
                        - In the top menu bar, click 
                           					 Native. 
                           				  
                        
- In the 
                           					 Native Navigation pane, expand 
                           					 Directory Server. 
                           				  
                        
- Click the 
                           					 region you require. 
                           				  
                        
- Click 
                           					 . 
                           					 
                           This opens the 
                              						Communications Server Properties page. 
                              					 
                            
- In the 
                           					 Native Listener Navigation pane, click the listener you require. 
                           				  
                        
- Click 
                           					 TLS Settings. 
                           				  
                        
- Check 
                           					 Enable TLS. 
                           				  
                        
- In the 
                           					 Certificate File field, type the location of the TLS certificate on the machine where this region runs. 
                           				  
                        
- In the 
                           					 Keyfile field, type the location of the TLS key on the machine where this region runs. 
                           				  
                        
- Expand 
                           					 Advanced. 
                           				  
                        
- Check 
                           					 Honor Server Cipher List. 
                           				  
                        
- Click 
                           					 Apply. 
                           				  
                        
- Restart the 
                           					 region so the changes are applied. 
                           				  
                        
 Next time the 
                        				  region is started, the network endpoint will be TLS enabled.