Securing connections

The various interactions that occur on the Sametime server can be secured.

Desktop client to Sametime server
These are connections from client to server that happen on port 1533 to the Sametime Multiplexer (Mux) by default. Sametime has legacy encryption enabled by default. These connections can be secured over TLS 1.2.
Sametime server to LDAP server
By default the LDAP operations are not encrypted. It is recommended to enable encryption using TLS to encrypt sensitive user data , such as names and passwords. The secure port for LDAPS is typically 636 but may be different in your environment.
Decrypting SAML assertions
When Sametime server is configured for SAML, the Sametime server can validate the encrypted assertions are from the Identity Provider (IdP). These settings is used for the decryption.
Configuration scope
Sametime server can be configured to use key and trust stores at the global level, where all certificates are shared among the different community services. As an option they can be configured to use separate key and trust stores.