Replacing an existing personal certificate

Occasionally, you need to replace an existing personal certificate with a new certificate. This task discusses how to replace the existing personal certificate in the keystore. It searches all keystores for a signer certificate extracted from the original personal certificate, and places the signer of the new personal certificate in it's place. It also updates all of the certificate alias references in the security configuration with the new one.

Before you begin

The current certificate and the certificate replacement must exist in the same keystore before you can replace a certificate.
Alternative Method: To replace a self-signed certificate by using the wsadmin tool, use the replaceCertificate command of the AdminTask object. For more information, see the PersonalCertificateCommands command group for the AdminTask object article

About this task

Complete the following steps in the administrative console:

Procedure

  1. Click Security > SSL certificate and key management > Manage endpoint security configurations > {Inbound | Outbound} > ssl_configuration > Key stores and certificates > [keystore ].
  2. Under Additional Properties, click Personal certificates.
  3. Select the certificate to be replaced. The alias list must include the certificate to be replaced and the certificate to replace it with.
  4. Click Replace.
  5. Select a replacement certificate alias from the list.
  6. You can delete one of the following types of certificates:
    • Select Delete old certificate to delete the existing or expired certificate.
    • Select Delete old signers to delete the existing signer certificates.
  7. Click Apply.

Results

Your results depend on what you selected:
Task topic    

Terms and conditions for information centers | Feedback

Last updated: April 18, 2014 05:01 AM CDT
http://www14.software.ibm.com/webapp/wsbroker/redirect?version=phil&product=was-nd-iseries&topic=tsec_sslreplaceselfsigncert
File name: tsec_sslreplaceselfsigncert.html