Add keystore files

 

Add keystore files

A keystore contains both public keys and private keys. Public keys are stored as signer certificates, while private keys are stored as personal certificates. In WebSphere Application Server, adding keystore files to the configuration is different between client and server. For the client, a keystore file is added to a file, like the sas.client.props property file. For the server, a keystore file is added through the WebSphere Application Server administrative console.

Before you add the keystore file to your configuration, consider the following questions:

 

Procedure

  1. Add a keystore file into a client configuration by editing the sas.client.props file and by setting the following properties:

    • com.ibm.ssl.keyStoreType for the keystore format. Range: JKS (default), PKCS12, JCEK.

    • com.ibm.ssl.keyStore for a fully qualified path to the keystore file. The keystore file contains private keys and sometimes public keys.

    • com.ibm.ssl.keyStorePassword for the password to access the keystore file.

  2. Add a keystore file into a server configuration:

    1. Start the administrative console by specifying: http://server_hostname:port_number/ibm/console.

    2. Click Security > SSL.

    3. Optional: Click New JSSE repertoire to create a new Java Secure Sockets Extension (JSSE) repertoire.

    4. Select the alias that you want to add into the keystore file.

    5. Type the key file name for the path of the keystore file.

    6. Type the key file password for the password to access the keystore file.

    7. Select the key file format for the keystore type. Range: JKS (default), PKCS12, JCEK or JCERACFKS (z/OS only).

    8. Click OK and Save to save the configuration.

 

Results

The SSL configuration alias now has a valid keystore file for an SSL connection.

Note: If the Cryptographic token field is selected and you want to use only cryptographic tokens for your keystore file, leave the Key file name field and the Key file password field blank.

Example





 

Related concepts


Secure Sockets Layer

 

Related tasks


Managing digital certificates
Configuring RMI over IIOP
Configuring Secure Sockets Layer for Java client authentication