EDI over AS2: Powered Aidant & Microsoft BizTalk
Context Regardless of the size, revenue or operations of our customers, the most common EDI overhead and hassle is dealing with VAN and their complicated setup and fees. Thankfully we have robust and secure protocols such as AS2 which work over the Internet. Aidant Technologies leverages best of BizTalk Server and its own SDK toolkits to integrate with trading partners over AS2. Its one-time setup that you can own and scale up, thereby removing the hassles and overhead of a VAN.
This white paper introduces considerations and technical information that you can use to help make this move. Whether you have an existing setup or want to set up new BizTalk environments, Aidant can help set the right course for your EDI RoadMap. Contact us for more information. www.aidant-tech.com/contact-us
EDI Approach/Considerations for AS2
- To Receive EDI over AS2 communication: There will be one URL given to Trading Partners to send the AS2 communications to HOME ROLE (SELF). The URL is public facing on the HOME ROLE (SELF) DMZ. After the message is received, the URL will be NAT’ed to the IIS Server inside HOME ROLE (SELF) Firewall which is hosted on local BizTalk Server (AS2 Web-Site). A Request-Response Type (2-Way) BizTalk Receive Port is set up to listen to the local IIS URL. The Receive Location will use AS2EDIReceive Pipeline for the receive side and AS2Send Pipeline on the send.
- To Send EDI over AS2 communication Once a message is ready to be sent out over AS2, a One Way Solicit Response Send Port is required which will use AS2EDISend Pipeline for the send side and AS2Receive for the receive side of the Send Port. The send side will assemble EDI, encrypt and sign the message with the customer public key and the receive side will be used to AS2 receive the MDN sent by the customer www.aidant-tech.com
WHITE PAPER
IIS Configuration for BizTalk AS2
Keys Components
• ISAPI Filters & Handler Mappings
• AS2 Web-Site and BizTalk App Pool
• Test the AS2 Web-site is reachable
Step 1: ISAPI Filters & Handler Mappings
Click Start, point to All Programs, point to Administrative Tools, and then click Internet Information Services (IIS) Manager.
Select the root Web server entry and in the Features View, double-click Handler Mappings and then in the Actions pane, click Add Script Map.
NOTE- In the Add Script Map dialog box, enter BtsHttpReceive.dll in the Request path field.
- In the Executable field, click the ellipsis (…) button and browse to drive:\Program Files\Microsoft BizTalk Server\HttpReceive. Select BtsHttpReceive.dll, and then click OK.
Configuring the script mapping at the Web server level will cause this mapping to apply to all child Web sites. Remove this mapping from the AS2 specific Web site or virtual folder under Default Web-Site.
Enter BizTalk HTTP Receive in the Name field, and then click Request Restrictions.
In the Request Restrictions dialog box, select the Verbs tab and then select One of the following verbs. Enter POST as the verb.
On the Access tab, select Script, and then click OK.
Click OK and when prompted to allow the ISAPI extension, click Yes.
Ensure that Read, Script, and Execute are selected, and then click OK.
Ensure that an entry for BTSHTTPReceive.dll exists, and that Restriction is set to Allowed.
WHITE PAPER
Step 2: AS2 Web-Site and BizTalk App Pool
In IIS Manager, right-click Application Pools and select Add Application Pool.
In the Add Application Pool dialog box, enter BizTalkAppPool in Name, and then select .NET Framework V2.0.50727 in the .NET Framework version drop-down list. Click OK.
NOTE- Select Application Pools, in the Features View select BizTalkApplicationPool, and then click Advanced Settings in the Actions pane. The version number may vary depending on the version of .NET Framework 2.0 installed on the machine.
In the Advanced Settings dialog box, set Enable 32-Bit Applications to True.
Select Identity and then click the ellipsis (…) button.
In the Application Pool Identity dialog box, select Custom account and then click Set.
Enter the User name and Password for a user account that is a member of the administrators group and is the BizTalk Service Account for the host that is running Receive and Send Handler Host for AS2 Ports/Adapter, enter the password in Confirm password and then click OK three times to return to the IIS Manager.
In IIS Manager, open the Sites folder. Right-click the Default Web Site, and then select Add Application.
In the Add Application dialog box, enter AS2Test in Alias, and then click Select.
In the Select Application Pool dialog box, select BizTalkAppPool and click OK.
Click Test Settings and verify that there are no errors displayed in the Test Connection dialog box. Click Close, and then click OK.
Step 3: AS2 Web-Site and BizTalk App Pool
- Create a default.htm in the HTTPReceive Folder under the BizTalk Install directory.
- In IIS Manager right-click the AS2 application and browse.
- The default browser should open and show the default.htm.
WHITE PAPER
Certificates
- Install Certificate Services on Windows Server 2008 by adding Certificates to the Server Roles.
- Generate a CSR from the Certificate Manager.
- Generate the Private certificate on the server.
- Install the Private Key on the BizTalk Server Certificate Store under Personal.
NOTE
- Generate a Public key and send this off to the External Trading Partners.
- Install External TP’s Public Certificate under Other People and Trusted People.
Alternatively, a certificate can be purchased from VeriSign® or other providers so that the CA Root Authority is more standard and available when dealing with outside Trading Partners. Especially when Servers are not exposed to the Internet.
- Select the Private certificate under BizTalk Server Group.
- Select TP’s Public Certificate under Send Port.
- Select self Public Certificate under Party.
- In the Select Application Pool dialog box, select BizTalkAppPool and click OK.
NOTE
All Certificate related activities and configuration above should be performed as BizTalk Service Account.
EDI Approach/Considerations for AS2
To Receive EDI over AS2 communication Once the message is received successfully, send ports for each respective party can be created to perform mapping functions to the canonical etc. Alternatively, if Orchestrations are used, direct binding can be done using similar or additional set of Context Properties from the BizTalkMsgBox. Context properties to be used:
- a. BTS.MessageType
- b. BTS.ReceivePortName
- c. EDI.ISA06
- d. EDI.ISA08
To Send EDI over AS2 communication
Setting up Ports and AS2 Party Receive Port – this should be a “Request-Response” Receive Port.
§ This is a common port that is created keeping in mind that all customer communications will come to the same port as explained in the approach above.ReceivePort All AS2
ReceiveLocation All AS2
Adapter Used: HTTP | URI: /{IIS Virtual Dir. Name under Default Web Site} Receive Pipeline: AS2EDIReceive Send Pipeline: ASSend AS2 Send Port for Trading PartnerCreate a new Send Port which is One Way Solicit Response Port. Create Configuration as follows:
- SP.CustomerName.All.AS2.Out
- Adapter Used: HTTP | URI: http://PartnerURL}
- Send Pipeline: AS2EDISend
- Receive Pipeline: AS2Receive
- Select the Partner Certificate under Certificates for this Send Port AS2 Party (Figure A1)
Create new Party. Right Click on the properties and then follow the screen shot below: Select the Send Port for AS2 Outbound created above under this party Send Ports.
- Also Select the Trading Partner Certificate under Party Properties-Certificates section (Figure A1/ click to enlarge) www.aidant-tech.com
WHITE PAPER
Certificate Setup
| Message or MDN | Direction | Certificate Type | Certificate Owner | Public or Private | Certificate Location | Where to configure |
|---|---|---|---|---|---|---|
| Message | Outbound | Signing | Home Org | Private | Personal certificate store of in-proc host user | BizTalk Group/Properties/Certificate |
| Message | Outbound | Encryption | Partner | Public | Other People certificate store of local computer | Send port/Certificate |
| Message | Inbound | Signing | Partner | Public | Other People certificate store of local computer | Party/Certificate |
| Message | Inbound | Encryption | Home Org | Private | Personal certificate store of in-proc host user | Isolated Host/Certificates |
| MDN | Outbound | Signing | Home Org | Private | Synch MDN: Personal certificate store of isolated host user Asynch MDN: Personal certificate store of in-proc host user | BizTalk Group/Properties/Certificate |
| MDN | Inbound | Signing | Partner | Public | Other People certificate store of local computer | Party/Certificate |