13.07.2015 Views

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

IBM WebSphere V5.0 Security - CGISecurity

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

There should now be the four key stores called:►►►►WASV5ServerKeyFile.jksWASV5ServerTrustFile.jksWASV5ClientKeyFile.jksWASV5ClientTrustFile.jksThere should also be two extracted certificates called:► WASV5IntSecPubCert.arm► WASV5ClientSecPubCert.arm10.9.2 Requesting a certificate signed by a CAThe ikeyman tool can be used to generate a certificate request. A certificate willbe required for the server and one for each client. The process documentedbelow is for the server’s key file although the process will be similar for everycertificate with only minor changes needed for each.1. Launch the ikeyman tool. It may be started from the command line in the bindirectory as ikeyman.bat (on Windows platforms) or ikeyman.sh (on UNIXplatforms)2. From the menu bar, select Key Database File -> New.3. Ensure that the Key database type is set to JKS. This section will use thefollowing file names to represent the appropriate key stores– WASV5ServerKeyFile.jks - server key file– WASV5ServerTrustFile.jks - server trust file– WASV5ClientKeyFile.jks - client key file– WASV5ClientTrustFile.jks - client trust file4. Enter WASV5ServerKeyFile.jks as the file name.5. Enter the directory that will hold the key file as the location, in this case:c:\<strong>WebSphere</strong>\Appserver\etc.6. Click OK.7. A password prompt will appear. Enter a password and repeat to confirm. Thispassword will be required to read from or write to this file in the future, so donot forget it. The password strength is determined by the variety of thecharacters used in the password8. Click OK.9. From the menu bar, select Create -> New Certificate Request.Chapter 10. Administering <strong>WebSphere</strong> security 271

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!