Secure HTTPS traffic for the BRMS web interface requires a digital certificate. A digital certificate provides two functions:
...
Expand |
---|
title | Creating the *SYSTEM certificate store |
---|
|
In a web browser, enter http://mysystem:2001/dcm, where mysystem is the host name or IP address of the system. This opens IBM Digital Certificate Manager for i. Log in with an IBM i profile with sufficient authority. Click on Create Certificate Store on the left-hand navigation menu On the right-hand side of the page select *SYSTEM.
 Info |
---|
Note: If the *SYSTEM option is not available in the list, it indicates that there is a *SYSTEM store already created on this system, and these steps have already been performed. |
Create a password for the *SYSTEM store and click Create.
Info |
---|
Note: The password is case-sensitive. It is recommended not to use special characters. This password is not attached to a user profile and it will not lock you out of the system after too many attempts. |
|
...
Expand |
---|
title | Creating the Local Certificate Authority |
---|
|
In a web browser, enter http://mysystem:2001/dcm, where mysystem is the host name or IP address of the system. This opens IBM Digital Certificate Manager for i. Log in with an IBM i profile with sufficient authority. Click on Create Certificate Store on the left-hand navigation menu. On the right-hand side of the page select Local CA. 
Info |
---|
Note: If the Local CA option is not available in the list, it indicates that there is already a local certificate authority on this system, and these steps have already been performed. |
Create a password for the Local CA store and click Create.
Info |
---|
Note: The password is case-sensitive. It is recommended not to use special characters. This password is not attached to a user profile and it will not lock you out of the system after too many attempts. |
ResultThe *SYSTEM certificate store is created on the node. |
Expand |
---|
title | Creating a Certificate Authority (CA) Certificate |
---|
|
In a web browser, enter http://mysystem:2001/dcm, where mysystem is the host name or IP address of the system. This opens IBM Digital Certificate Manager for i. Log in with an IBM i profile with sufficient authority. In the left-hand menu, select Local CA Image ModifiedIf Local CA is not in the left-hand menu, open it by doing the following: Select Open Certificate Store. Enter the password for the local certificate authority, and click open. The Local CA will now automatically be selected in the left-hand menu.
Under Certificate Authority (CA) Certificates, create one if one does not exist by selecting Create. Fill n the required fields. At a minimum: Common name: Provide a unique common name for this. For example: MyCompany MySystem CA Organization Name: Provide the name of your company State or Province: Provide the state or province of the system Country or Region: Provide the two character country code Image Added Image Modified
Click Create.
ResultThe CA Certificate is created on the node. |
Expand |
---|
title | Creating a Self-Signed Certificate |
---|
|
In a web browser, enter http://mysystem:2001/dcm, where mysystem is the host name or IP address of the system. This opens IBM Digital Certificate Manager for i. Log in with an IBM i profile with sufficient authority. In the left-hand menu, select the *SYSTEM certificate store. Image ModifiedIf the *SYSTEM certificate store is not in the left-hand menu, open the certificate store: Select Open Certificate Store in the left-hand menu. Select *SYSTEM on the right-hand side of the screen. Image ModifiedEnter the password for the *SYSTEM certificate store. Click Open.
Under certificates on the right-hand side, select Create. Image ModifiedFor type, select Local CA Fill in the required fields. At a minimum: Label: Provide a unique common name for this. For example: MyCompany MySystem BRMS Web Interface Organization Name: Provide the name of your company State or Province: Provide the state or province of the system Country or Region: Provide the two character country code
Click Create.
ResultThe self-signed certificate is created on the node. |
1.b Importing a Trusted Certificate
...
Expand |
---|
title | Assigning the Certificate to the BRMS Webserver |
---|
|
In a web browser, enter http://mysystem:2001/dcm, where mysystem is the host name or IP address of the system. This opens IBM Digital Certificate Manager for i. Log in with an IBM i profile with sufficient authority. In the left-hand menu, select the *SYSTEM certificate store. Image ModifiedIf the *SYSTEM certificate store is not in the left-hand menu, open the certificate store: Select Open Certificate Store in the left-hand menu. Select *SYSTEM on the right-hand side of the screen. Image ModifiedEnter the password for the *SYSTEM certificate store. Click Open.
Select Manage Application Definitions. Image Modified Image Removed
Image RemovedSearch for QIBM_QBRM_WEB. Click on the + symbol at the lower-right of the QIBM_QBRM_WEB box. Click on Assign Certificates. Click the box for the certificate you wish to assign, and click Assign.
|
3. Enabling the secure HTTPS server
...