Install the Provisioning Server Certificate
The following operating system components must be installed on your iSeries machine to use SSL:
On the iSeries
C:\Program Files\CA\Identity Manager\Provisioning Server\Data\Tls\et2_cacert.pem
Using a web browser, go to http://<hostname>:2001. When prompted, log on as QSECOFR and click the Digital Certificate Manager link
Click the 'Select a Certificate Store' button and select the *SYSTEM certificate store. If this store does not exist, create a new store called *SYSTEM and then enter the certificate store password.
Click Manage Certificates, Import Certificate and select the Certificate Authority (CA) option and then enter the file name of the Provisioning server certificate. (This is where you uploaded the certificate in step 1). Enter a label for the certificate: Provisioning Server Importing the certificate is complete.
sure that the IBM Directory client QIBM_GLD_DIRSRV_CLIENT can access the *SYSTEM
keystore. Otherwise, the SSL initialization call of the PSA fails.
The Provisioning Server certificate should be listed here if imported correctly from step 4.
Click 'Trusted' for the Provisioning Server certificate and click OK at the bottom of the list.
(/QIBM/userdata/ICSS/Cert/Server/default.kdb)
Grant read and execute permission to the parent folder
(/QIBM/userdata/ICCS/Cert/Server)
Note: Adopting authority of user PWDSYNCH does not work in the / file system, so access must be granted for all users.
Copyright © 2011 CA. All rights reserved. | Email CA Technologies about this topic |