To participate in AIS, please visit the following site (https://www.us-cert.gov/ais) and follow the 4 step process stated.
Once you get an email back from Taxiiadmin, please use the following configuration guide to set up a DHS/AIS site on your CTX/Soltra Edge appliance.
Log into your CTX/Soltra Edge appliance
Create your Site by populating the following fields and select the blue Add Site button
Site Name – Enter a name of your choosing
Login – leave this area blank
Discovery URL – https://taxii.dhs.gov:8443/flare/taxii/discovery
STIX Profile – DHS AIS
** - discovery will initially fail, to be expected (cert error)
Select the site you just created
Select Connection and choose the blue Upload button
Copy and paste your public and private key into the necessary fields **
Enter the passphrase used in the creation of your certificate, if you are provided a passphrase **
Select the blue Enable Two-Way button
Once you enable Two-Way, CTX/Soltra Edge will work to discover the DHS Taxii server. You can see the status of this connection in the discovery window in the upper right corner of the Site page.
Select Feeds and click the blue “+” sign
Select what poll configuration you want for your appliance
Periodic – input an amount of time to poll automatically in minutes
Example – 60 for 60 minutes
Example – every 5 minutes, your appliance will perform a poll of the feed
Manual – input a time to start the sync
Example – 2017-05-13 00:00:00
This translates to year-month-day hour:minute:second
Select the blue Configure Feed button
You now will see your configured feed as shown below.
Click on your configured feed, and select Options (Blue AIS feed – example screenshot)
Type in the Subscription ID you receive from DHS and select the blue Update button
The public and private keys that will be copied/pasted in step 7 are the certificates you receive from your certificate vendor. You will not use the certificates you receive from TaxiiAdmin.
If you did not use a passphrase in the creation of your certificate, leave this area blank
For more information, join the conversation in the CTX/Soltra Edge Forums at forums.soltra.com.