Configure SSL Certificates in WebSphere application Server:Step A: Configuring key store, refer steps mentioned below. Refer 5.1 screenshot.
1. Open IBM Admin Console
2. On the Left-hand side expand Security.
3. Click of “SSL certificate and key management”
4. Click on “Key stores and certificates”.
5. Add a new Key Store (Click on “New button”)
6. Fill in the following information:
- Name – Any name can be given e.g. platformssl
- Path – Provide .jks file path that is created in step 1
- Password – provide password of keystore (password)
- Confirm password – confirm password of keystore (password)
- Type : select JKS (Unica J2EE application support JKS keystores only)
- Click Ok. After the page refreshes, click save link on center top.
1. Click on “SSL certificate and key management” again.
2. Click on “Manage endpoint security configurations”
3. In the Local Topology view you will see 2 Topologies, Inboud and outbound.
4. In the Inbound topology you will see a tree and at the bottom of the tree, you will see a link which reads like [machinename][NodeName]([SSL Configuration Name], [keystorename]),[Keystore Alias Name].
5. Click on the link mentioned above.
6. Click on “SSL Configuration”.
7. Create a new Secure Sockets Layer (SSL) configurations (Click on New button)
8. Fill in the following information:
1. Name: Provide an intuitive name.
2. Select the Key store name you just added in the Trust Store Name.
3. Select the Key store name you just added in the Keystore Name. Click on Get certificate aliases. This will populate all the aliases available in the selected key store to the two drop downs “Default server certificate alias” and “Default client certificate alias”
4. Select the desired alias in “Default server certificate alias”
5. Select the desired alias in “Default client certificate alias”
Changes will be reflected as mentioned in Image 5.3
10. Once the page refreshes click save link on the center top of the page.
11. Click on the link SSL certificate and key management > Manage endpoint security configurations > [NodeName].
12. You will see General Properties. Refer Image 5.4
13. Under the general properties you will see your Node name.
14. Make sure the value of direction is inbound.
15. Select the newly added SSL Configuration (e.g. platformssl_cert) in the ‘SSL Configuration’ drop down.
16. Click on button ‘Update certificate alias list’. This will update the drop down ‘Certificate alias in key store’
17. from the ‘Certificate alias in key store’ drop down, select the alias you desire to use.
18. Click Ok. When the page refreshes click save link.
Step C: Import the Campaigncert.arm file into the application server where the Campaign web application is deployed (Refer Image 5.5)
Open WAS console and navigate to:
- Security > SSL Certificate and key management > Key stores and certificates
- Click on NodeDefaultTrustStore -> Signer certificates -> Add signer certificate
- Add details as campaign_listener
- Path for Campaigncert.arm file
- Click on Apply
- Click on save changes on top of the screen