+

Search Tips   |   Advanced Search

 

Retrieve signers from a remote SSL port

 

Overview

To perform SSL communication with a server, WAS must retrieve a signer certificate from a secure remote SSL port during the handshake. After the signer certificate is retrieved, you can add the signer certificate to a keystore.

The keystore that is to contain the signer certificate must already exist.

 

Procedure

  1. Click...

    Security | SSL certificate and key management | Manage endpoint security configurations | {Inbound | Outbound} | Key stores and certificates | keystore | Signer certificates | Retrieve from port

  2. Click Retrieve from port.

  3. Type the host name of the machine on which the signer resides.

  4. Type the port location on the host machine on which the signer resides. The port location is not limited to ports on WebSphere Application Server. The ports can include LDAP ports or ports on any server on which an SSL port is already configured, such as...

    SIB_ENDPOINT_SECURE_ADDRESS

  5. Select an SSL configuration for the outbound connection from the list.

  6. Type an alias name for the certificate.

  7. Click Retrieve signer information. A message window displays information about the retrieved signer certificate, such as: the serial number, issued-to and issued-by identities, SHA hash, and expiration date.

  8. Click Apply. This action indicates that you accept the credentials of the signer.

 

Results

The signer certificate that is retrieved from the remote port is stored in the keystore.

 

What to do next

An SSL configuration or client process that requires an SSL connection to the server can use the retrieved and approved signer certificate.

To retrieve a signer certificate from a port using the wsadmin tool, use the retrieveSignerFromPort command of the AdminTask object. For more information, see PersonalCertificateCommands command group for the AdminTask object.



Retrieve from port

 

Related concepts

Secure Sockets Layer configurations
Dynamic outbound selection of Secure Sockets Layer configurations
Keystore configurations

 

Related Reference


SignerCertificateCommands command group for the AdminTask object