Adding a signer certificate to a keystore

Signer certificates establish the trust relationship in SSL communication. You can extract the signer part of a personal certificate from a keystore, and then you can add the signer certificate to other keystores.

Before you begin

The keystore that you want to add the signer certificate to must already exist.
Alternative Method: To add a signer certificate to a keystore by using the wsadmin tool, use the addSignerCertificate command of the AdminTask object. For more information, see the SignerCertificateCommands command group for the AdminTask object article.

About this task

Complete the following steps in the administrative console:

Procedure

  1. Click Security > SSL certificate and key management > Manage endpoint security configurations > Inbound | Outbound > ssl_configuration > Key stores and certificates.
  2. Select a keystore from the list of keystores.
  3. Click Signer certificates.
  4. Click Add.
  5. Enter an alias for the signer certificate in the Alias field
  6. Enter the full path to the signer certificate file in the File name field.
  7. Select a data type from the list in the Data type field.
  8. Click Apply.

Results

When these steps are completed, the signer from the certificate file is stored in the keystore. You can see the signer in the keystore files list of signer certificates. Use the keystore to establish trust relationships for the SSL configurations.



In this information ...


IBM Redbooks, demos, education, and more

(Index)

Use IBM Suggests to retrieve related content from ibm.com and beyond, identified for your convenience.

This feature requires Internet access.

Task topic    

Terms of Use | Feedback

Last updated: Oct 22, 2010 12:21:29 AM CDT
http://www14.software.ibm.com/webapp/wsbroker/redirect?version=compass&product=was-nd-zos&topic=tsec_ssladdsignercert
File name: tsec_ssladdsignercert.html