To participate in an SSL session, TheirCo's i5/OS™ File Transfer Protocol (FTP) client must be able to recognize and accept the certificate that MyCo's FTP server presents to establish the Secure Socket Layer (SSL) session. To authenticate the server certificate, TheirCo's FTP client must have a copy of the Certificate Authority (CA) certificate in the *SYSTEM certificate store. The *SYSTEM certificate store contains a copy of most public CA certificates. However, when MyCo's FTP server uses a certificate from a local CA, the TheirCo's FTP client must obtain a copy of the local CA certificate and import it into the *SYSTEM certificate store.
This scenario assumes that Digital Certificate Manager (DCM) has not been previously used to create or manage certificates. Consequently, TheirCo must first create the *SYSTEM certificate store by following these steps: