How to Configure AS2
A site administrator configures AS2 on your site.
AS2 requires that you and your trading partner agree on identifiers for your communication. These are sometimes referred to as "AS2 Identity", "AS2 name", "AS2 code", "AS2 station", or "AS2 To and AS2 From" identifiers.
You need your own x509 Certificate and Key for decryption and digital signing. We can generate this for you, or you can provide your own. Self-signed certificates work. Your generated public Certificate and private Key must be in PEM or CRT format. These certificates decrypt data received from your trading partner and digitally sign data sent to your trading partner.
You provide the public x509 Certificate to your trading partner.
You need your trading partner's public x509 Certificate for encryption. Contact your trading partner and ask them to provide the public AS2 certificate for this connection. This certificate encrypts data you send to your trading partner and validates the digital signature of data received from your trading partner.
You need the AS2 URL of your trading partner, sometimes referred to as the "endpoint URL". Contact your trading partner and ask them to provide the AS2 URL for this connection. This URL is used to connect to your trading partner's AS2 system and deliver data.
Configuring Your AS2 Identity
You can create as many AS2 identities as your business requires. Most organizations have a single AS2 Identity, but some require multiple identities to represent, and route data to, subsidiaries or business units.
Enter your desired AS2 Identity, then paste your public certificate and private Key, or generate the certificate and key in our web interface.
When providing your own, your public certificate and private key must be in PEM or CRT format and must be a matching pair. Files.com uses the private key to decrypt messages encrypted for your certificate and to sign outgoing messages that your trading partner verifies with that certificate. A key from another pair cannot perform those operations.
A password-protected private key requires its password when imported. The API accepts the password in private_key_password when creating or updating an AS2 identity. An unencrypted private key does not require a password.
Your public Certificate begins with -----BEGIN CERTIFICATE----- and ends with -----END CERTIFICATE-----.
Private key headers include -----BEGIN PRIVATE KEY-----, -----BEGIN RSA PRIVATE KEY-----, and -----BEGIN ENCRYPTED PRIVATE KEY-----, each with its corresponding END line. Include the complete key, including those lines. The ENCRYPTED PRIVATE KEY form requires a password; RSA private keys can also be password protected.
You can use fully valid and chained Certificates and Keys, or use self-signed Certificates and Keys.
Generating Your Encryption and Signing Certificates
We provide a built-in generator within the Add new AS2 identity function that generates self-signed certificates and keys for you.
Your IT department or your SSL Certificate provider can provide fully valid and chained Certificates and Keys. You, or your IT department, can also generate your own self-signed Certificates and Keys.
To generate self-signed Certificates and Keys yourself, use the openssl command:
openssl req -x509 -days 365 -newkey rsa:2048 -keyout key.pem -out certificate.pem -nodes
Your trading partners view this Certificate to identify you and your business details, so it must contain accurate information.
When prompted by openssl, enter the following information:
| Item | Description |
|---|---|
| Country Name | Enter the 2 letter code for the country. For example, "US". |
| State or Province Name | Enter the full name of the State or Province. For example, "California". |
| Locality Name | Enter the full name of the city, town, village, or locality. For example, "San Francisco". |
| Organization Name | Enter the full name of your business or company. For example, "Files.com". |
| Organizational Unit Name | Enter the full name of your department, division, or team. For example, "Partner Relations". |
| Common Name | Enter the fully qualified domain name (FQDN) of your AS2 URL, or the fully qualified domain name of your business, that this certificate represents. For example, "mysite.files.com" or "mydept.mycompany.com". |
| Email Address | Enter a valid email address for your trading partners to use to contact you in case of any problems or questions about this certificate. |
Converting Certificate Types
Files.com AS2 supports PEM and CRT encoded certificates and keys.
You can use openssl to create and convert certificates and keys.
There are also various online guides and tutorials available describing how to convert certificates from one type to another.
Configuring Trading Partners
Enter the trading partner's AS2 URL, as provided to you by your trading partner. The URL can include the Fully Qualified Domain Name (FQDN), or IP address, of the trading partner, the port number (if a non-standard port is being used), and subdirectory path.
Enter the trading partner's AS2 Identity, as agreed upon between you and your trading partner.
Paste in the trading partner's public encryption Certificate. The public Certificate must be in PEM or CRT format.
The public Certificate begins with -----BEGIN CERTIFICATE----- and ends with -----END CERTIFICATE-----.
You can use fully valid and chained public encryption Certificates, or self-signed public encryption Certificates. Your trading partner supplies you with this certificate.
Select which of your AS2 Identities you want to use with this trading partner.
Choose the Server certificate option that corresponds to the security level of the trading partner's AS2 URL.
If your trading partner's AS2 URL is protected by a valid and chained SSL Certificate, choose the "Require valid, chained, trusted, matching TLS/SSL certificate (Recommended)" option.
If your trading partner's AS2 URL uses a self-signed, unchained, expired, or non-matching SSL Certificate, choose the "Allow self-signed, unchained, expired, or non-matching TLS/SSL certificate" option.
If your trading partner's AS2 URL uses Basic Authentication, requiring an AS2 username and password, use the Enable Basic Authentication option. Provide the AS2 username and password to use when sending messages to this trading partner.
Files.com sends outgoing AS2 messages signed and encrypted. For incoming messages, your partner can send signed or unsigned messages, with or without S/MIME message encryption, subject to the signature validation level below. Agree on those choices with your partner independently: a requirement for a valid signature does not require message encryption, and message encryption does not satisfy a signature requirement. HTTPS transport encryption protects the connection even when the incoming message has no S/MIME encryption.
Choose an MDN validation level for receipts this trading partner returns for your outgoing messages. This option determines how much validation is performed on the returned MDN to consider the AS2 transmission a success.
| Validation Level | Description |
|---|---|
| None | The returned MDN is not validated. Use this level when a valid MDN is not required by your business process. |
| Weak | The returned MDN must contain a valid Message Integrity Check (MIC) and a valid Disposition. No MDN Signature required. |
| Normal | The returned MDN must contain a valid Message Integrity Check (MIC) and Disposition, and its Signature must verify against the configured trading partner certificate. That certificate can be self-signed or lack an S/MIME signing purpose. |
| Strict | The returned MDN must contain a valid Message Integrity Check (MIC) and Disposition, and its Signature must verify against the configured trading partner certificate. That certificate must also be valid, fully chained, and configured for S/MIME signing purposes. |
| Auto | The first, or next, returned MDN is used to automatically determine the highest level of MDN validation applicable for this partner. After processing that MDN, the setting changes from Auto to the selected validation level, which is displayed in the trading partner's settings and used for future transmissions. Auto is the default when creating a new trading partner. |
At Normal and Strict, a signature made with a different key fails validation. Verifying against the configured partner certificate ties the signed receipt to the key you exchanged with that partner. If your partner changes their signing key, update their configured certificate at the agreed time.
Auto helps establish a compatible validation requirement when setting up a trading partner. It selects Normal only when the receipt passes Normal's checks, including signature verification against the configured partner certificate. If the MIC and Disposition are valid but the signature is absent or does not verify against that certificate, Auto selects Weak. Choose Normal or Strict explicitly when your business process requires a signed receipt verified with the partner's configured certificate.
Saving the selected level gives later transmissions a consistent requirement: a subsequent receipt that fails that level fails validation instead of causing Auto to select a weaker level for it.
Choose a signature validation level for incoming AS2 messages from this trading partner. This setting is separate from MDN validation, which applies to receipts returned for your outgoing transmissions. Use Normal when incoming messages must have a valid signature.
| Validation Level | Description |
|---|---|
| Normal | Incoming AS2 messages must have a signature that verifies against the configured partner certificate and matches the signed content. The certificate's chain, signing purpose, and validity dates are not checked. |
| None | Incoming AS2 messages do not require a signature, and signature validation is skipped. |
| Auto | The next incoming message selects Normal if its signature validates against the configured partner certificate, or None otherwise. The selected level replaces Auto for subsequent messages. Auto is the default for a new trading partner. |
Normal verifies that the message was signed with the private key corresponding to the configured partner certificate and that the signed content is unchanged. It rejects unsigned messages, signatures made with a different key, and content that does not match the signature. Self-signed certificates, certificates without an S/MIME signing purpose, and certificates that are expired or not yet valid can all validate signatures at this level. The same rules apply when Auto selects Normal.
This keeps incoming business exchanges running while you coordinate certificate renewal with your partner. The expiration date shown in the AS2 Trading Partners table helps you plan that renewal; it does not stop acceptance of incoming signatures at Normal. Update the configured certificate or delete the trading partner when you need to change the accepted signing key or end the partnership.
Files.com returns a signed MDN with a Message Integrity Check (MIC) for successfully processed incoming messages, including unsigned messages. The receipt acknowledges the received content; its signature and MIC do not establish that the incoming message was signed or that its signature was validated.
You can configure additional HTTP headers for AS2 transmissions to the trading partner. This is useful when your trading partner applies additional HTTP protection to their AS2 service that requires custom headers to approve the transmission. Only use this setting if your trading partner requires it.
You can specify the MIME type of the AS2 transmissions to the trading partner. By default, Files.com attempts to automatically infer the MIME type and uses that for the transmission. If the MIME type cannot be inferred, a type of application/octet-stream is used. Configure this setting if your trading partner requires you to define a specific MIME type for your transmissions to them.
Select your preference for the Dedicated IPs setting for this trading partner. The option for specifying the use of Dedicated IPs only appears if your site is configured to allow that option. Dedicated IPs are only available when a Custom Domain has been configured. We recommend using Dedicated IPs when your trading partner's firewall only allows connections from specified IP addresses.
Message Retention
The system retains all AS2 messages, including their full payloads and debugging details, for 90 days by default. You can adjust this duration in the Message Retention Timeframe setting.
This retention setting applies globally to your entire site and includes both inbound and outbound AS2 messages. It controls how long message logs and message content remain available before they are automatically removed.
AS2 Data Residency
Retained AS2 message data is stored in the United States, regardless of the storage region configured for the rest of your site. This covers the AS2 message logs, the message payloads, and the transmitted file contents, and it applies even when the transmitted file is not otherwise stored in Files.com. Files.com's AS2 logging infrastructure runs in the United States, and there is no setting to change where AS2 data is stored.