WAS v8.5 > Secure applications > Secure communications

Create a keystore configuration for a preexisting keystore file

An SSL configuration references keystore configurations during security processing. If another keystone tool is used to create a keystore file, or the keystone file was saved from a previous configuration, create a new keystone configuration object that references the preexisting keystone file. The server then uses this new keystone configuration object to obtain information from the preexisting keystone file.

A keystore must already exist.

Alternative Method: To create a keystore using wsadmin, use the createKeyStore command of AdminTask. For more information, see the KeyStoreCommands command group for AdminTask article.

Complete the following steps in the dmgr console:

  1. Click Security > SSL certificate and key management > Manage endpoint security configurations > {Inbound | Outbound}.

  2. Under Related Items, click Key stores and certificates, then click New.

  3. Type a name in the Name field. This name uniquely identifies the keystore in the configuration.

  4. Type the location of the keystore file in the Path field. The location can be a file name or a file URL to an existing keystore file.

  5. Type the keystore password in the Password field. This password is for the keystore file that you specified in the Path field.

  6. Type the keystore password again in the Confirm Password field to confirm the password.

  7. Select a keystore type from the list. The type that you select is for the keystore file that you specified in the Path field.

  8. Select any of the following optional selections:

    • The Read only selection creates a keystore configuration object but does not create a keystore file. If this option is selected, the keystore file that you specified in the Path field must already exist.
    • The Initialize at startup selection initializes the keystore during runtime.
    • The Enable cryptographic operations on a hardware device specifies whether a hardware cryptographic device is used for cryptographic operations only.

      Operations that require login are not supported when using this option.

  9. Click Apply and Save.


Results

You have created a keystore configuration object for the keystore file that you specified. This keystore can now be used in an SSL configuration.


Subtopics


Related concepts:

Keystore configurations for SSL
SSL configurations


Reference:

Keystores and certificates exchange signers
KeyStoreCommands command group for AdminTask


+

Search Tips   |   Advanced Search