03.05.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

publicly circulating root certificate authorities (CAs). In this case, optionally<br />

delete all of the CA trusted signer certificates.<br />

7. From the ikeyman menu, select Create -> New Self-Signed Certificate to<br />

create a new self-signed certificate key pair. The following options then need<br />

to be specified; you may choose to complete all of the remaining fields for the<br />

sake of completeness:<br />

Key Label: WASplugin<br />

Version: X509 V3<br />

Key Size: 1024<br />

Common Name: websrv01.itso.ibm.com<br />

Organization: <strong>IBM</strong><br />

Country: US<br />

Validity Period: 365<br />

Click OK when you are finished.<br />

8. Extract the public self-signed certificate key, as this will be used later by the<br />

embedded HTTP server peer to authenticate connections originating from the<br />

plug-in.<br />

9. Select Personal Certificates in the drop-down menu and select the<br />

WASplugin certificate that just was created.<br />

10.Click the Extract Certificate button, ensuring that WASplugin remains<br />

selected. Extract the certificate to a file:<br />

Data type: Base64-encoded ASCII data<br />

Certificate file name: WASpluginPubCert.arm<br />

Location: c:\<strong>IBM</strong>HttpServer\conf\keys (or the directory of your choice)<br />

Click OK when you are finished.<br />

11.Close the key database and quit ikeyman when you are finished.<br />

Generating a self-signed certificate for the Web Container<br />

The following steps will show how to generate a self-signed certificate for the<br />

<strong>WebSphere</strong> Web Container.<br />

1. Launch the <strong>IBM</strong> JKS capable ikeyman version that ships under the<br />

<strong>WebSphere</strong> bin directory. On Windows systems, start it with the ikeyman.bat<br />

command, on UNIX systems run the ikeyman.sh script.<br />

2. From the ikeyman menu select Key Database File -> New.<br />

304 <strong>IBM</strong> <strong>WebSphere</strong> <strong>V5.0</strong> <strong>Security</strong> Handbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!