WAS v8.5 > Secure applications > Secure communications > Create a certificate authority requestReceive a certificate issued by a certificate authority
When a certificate authority (CA) receives a certificate request, it issues a new certificate that functions as a temporary placeholder for a CA-issued certificate. A keystore receives the certificate from the CA and generates a CA-signed personal certificate that WebSphere Application Server can use for SSL security.
The keystore must contain the certificate request that was created and sent to the CA. Also, the keystore must be able to access the certificate that is returned by the CA.
To receive a certificate using wsadmin, use the receiveCertificate command of AdminTask. For more information, see the PersonalCertificateCommands command group for AdminTask article.
WAS can receive only those certificates that are generated by a WAS certificate request. It cannot receive certificates created with certificate requests from other keystore tools, such as iKeyman and keyTool.
Complete the following steps in the dmgr console:
- Click Security > SSL certificate and key management > Manage endpoint security configurations > {Inbound | Outbound} > ssl_configuration > Key stores and certificates > [keystore].
- Under Additional Properties, click Personal certificates.
- Select a personal certificate.
- Click Receive a certificate from a certificate authority.
- Type the full path and name of the certificate file.
- Select a data type from the list.
- Click Apply and Save.
Results
The keystore contains a new personal certificate that is issued by a CA. The original certificate request is changed to a personal certificate.
The SSL configuration is ready to use the new CA-signed personal certificate.
Subtopics
- Export certificate to a keystore file or a managed keystore
Use this page to specify a personal certificate to export to a keystore file or a managed keystore.- Import certificate from a key file or managed keystore
Use this page to specify a personal certificate to import from a keystore or key file.- Receive certificate from CA
Use this page to import your personal certificate from the certificate authority (CA). The imported certificate replaces the temporary certificate associated with the public/private keys in the certificate request stored in the key store.- Export certificate to a keystore file or a managed keystore
Use this page to specify a personal certificate to export to a keystore file or a managed keystore.- Import certificate from a key file or managed keystore
Use this page to specify a personal certificate to import from a keystore or key file.- Receive certificate from CA
Use this page to import your personal certificate from the certificate authority (CA). The imported certificate replaces the temporary certificate associated with the public/private keys in the certificate request stored in the key store.
Related concepts:
SSL configurations
Keystore configurations for SSL
Related
Create a certificate authority request
Reference:
PersonalCertificateCommands command group for AdminTask