Importing the Content Assistant root certificate into traditional Content Platform Engine deployments

Import the Content Assistant root certificate into the WebSphere® Application Server truststore to enable integration with traditional Content Platform Engine deployments.

About this task

To integrate the Content Assistant with your FileNet Content Manager traditional WebSphere Application Server deployments, you must first import the Content Assistant root certificate in Privacy Enhanced Mail (PEM) format into the WebSphere Application Server truststore.

Procedure

  1. Get the Content Assistant root certificate.
    To get the root certificate, you can access the following Content Assistant SaaS service URL by using a browser:
    https://filenetai.saas.ibm.com/prod
  2. Log in to the WebSphere Integrated Solutions Console as an administrator.
  3. Go to Security > SSL certificates and key management.
  4. Go to the signer certificates page, depending on the type of your WebSphere installation:
    Option Description
    WebSphere base edition or stand-alone environment Key stores and certificates > NodeDefaultTrustStore > Signer certificates
    WebSphere ND Key stores and certificates > CellDefaultTrustStore > Signer certificates
  5. Add the Content Assistant certificate from step 1 into the WebSphere Application Server truststore.
    • (Option 1) - Add a local Content Assistant certificate.
      1. Download the Content Assistant root certificate in .pem format. Refer to the browser documentation to download and save the certificate.
      2. Click Add.
      3. Type a certificate alias in the Alias field.
      4. In the File Name field, type the file name and path to where the certificate is located.
      5. Click OK.
    • Option 2 - Retrieve the Content Assistant certificate from a remote port.
      1. Click Retrieve from port.
      2. Enter the Host name of the remote server. Use the OpenShift route associated with your deployment as the host name.
      3. Specify the SSL port information.
      4. Type a certificate alias in the Alias field.
      5. Click Retrieve Signer Information and click OK.
  6. Save the changes to the master configuration.
  7. Restart the Content Platform Engine instances on the application server.