You must use Digital Certificate Manager (DCM) to assign a certificate
to an application before the application can perform a secure function, such
as establishing a Secure Sockets Layer (SSL) session or signing an object.
To assign a certificate to an application, or to change the
certificate assignment for an application, follow these steps:
- Start
DCM.
- Click Select a Certificate Store and select
the appropriate certificate store. (This is either the *SYSTEM certificate
store or the *OBJECTSIGNING certificate store depending on the type of application
to which you are assigning a certificate.)
Note: If you have questions
about how to complete a specific form in this guided task, select the question
mark (?) at the top of the page to access the online
help.
- When the Certificate Store and Password page displays, provide
the password that you specified for the certificate store when you created
it and click Continue.
- In the navigation frame, select Manage Applications to
display a list of tasks.
- If you are in the *SYSTEM certificate store, select the type of
application to manage. (Select either Server or Client application,
as appropriate.)
- From the task list, select Update certificate assignment to
display a list of applications for which you can assign a certificate.
- Select an application from the list and click Update
Certificate Assignment to display a list of certificates that
you can assign to the application.
- Select a certificate from the list and click Assign
New Certificate. DCM displays a message to confirm your certificate
selection for the application.
Note: If you are assigning a certificate
to an SSL-enabled application that supports the use of certificates for client
authentication, you must
define
a CA trust list for the application. This ensures that the application
can validate only those certificates from CAs that you specify as trusted.
If users or a client application presents a certificate from a CA that is
not specified as trusted in the CA trust list, the application will not accept
it as a basis for valid authentication.
When you change or remove a certificate for an application, the
application may or may not be able to recognize the change if the application
is running at the time you change the certificate assignment. For example, iSeries™ Access for Windows® servers will apply any certificate
changes that you make automatically. However, you may need to stop and start
Telnet servers, the IBM® HTTP Server for i5/OS™,
or other applications before these applications can apply your certificate
changes.
In OS/400® V5R2
or later, you can use the Assign
certificate task when you want to assign a certificate to several applications
at once.