Automatic SSL initialization
To initialize SSL automatically, do the following steps:
- If the connection between the service processor and the iSeries™ uses a shared
network, consider temporarily connecting the service processor and the iSeries with an isolated network. If you do not, the automatic method is slightly
less secure than the manual methods during the short time it takes for the
Initialize task in step 3 to run.
- Use the procedure described in Change service processor configuration properties to change
the properties of the service processor configuration for the server. Go
to the Security tab and select the Automatically set up user and generate certificate option. Press OK
to save the change.
-
Use the procedure described in Initialize a service processor to
initialize the service processor:
- Specify the Initialize a new service processor option.
Note:
Use the Synchronize certificate from service processor option if this is an additional service processor configuration used
for the same service processor that has already been previously initialized
for use with another integrated server.
- Specify the User and Password values.
- Press Initialize to perform the operation.
Note:
The service processor automatically generates a self-signed
certificate, which is stored by i5/OS™. The certificate is stored in the integrated
file system directory /QIBM/UserData/Director/classes/com/ibm/sysmgt/app/iide/
with a file name that matches the name of the service processor configuration.
This file will have a 'kdb' extension.