Prerequisites
Confirm you have the following files from Paxos onboarding before proceeding:1. Verify Network Connectivity
Test basic connectivity to confirm the server and port are reachable:- DNS resolution failures or an incorrect server address
- Firewall rules blocking outbound traffic on port
4199 - Your IP address not being allowlisted (see Check Your External IP)
2. Verify Server Certificate
Use OpenSSL to confirm the server returns a certificate during the connection attempt:no peer certificate available, contact Support.
3. Check Your External IP
Your external IP address may need to be added to the Paxos allowlist. Find it with:4. Configure Stunnel
If your FIX client does not support native TLS, use Stunnel as a TLS proxy. Below is a sample configuration:debug = 7.
5. Validate Your Certificate
Confirm your signed certificate validates against your CA:your_signed_certificate.crt: OK.
6. Test the Connection
Run a full mTLS connection test using all three certificate files:7. Verify File Format
Each certificate and key file must use proper PEM formatting. Confirm each file contains the correctBEGIN and END markers:
Missing or malformed headers indicate a corrupted or incorrectly formatted file.
8. Match Certificate and Private Key
Verify the certificate and private key are a matched pair by comparing their MD5 checksums — both values must be identical:9. Check Certificate Expiration
Verify your certificate has not expired:10. Verify Software Versions
Confirm you are running supported versions of Stunnel and OpenSSL:- Stunnel v4.54 or higher
- OpenSSL with TLS 1.2 support or higher
Questions? Contact Support.