Adding a CA root digital certificate

After you have requested and received a root digital certificate from a CA, you can add it to your database.

Most root digital certificates are of the form *.arm, such as the following example:

cert.arm

To add a CA root digital certificate to a database, use the following procedure:

  1. Unless you are already using Key Manager, start the tool by typing:
    # certmgr
  2. From the main screen, select Open from the Key Database File list.
  3. Highlight the key database file to which you want to add a CA root digital certificate and click Open.
  4. Enter the password and click OK. When your password is accepted, you are returned to the IBM® Key Management screen. The title bar now shows the name of the key database file you selected, indicating that the file is now open and ready to be worked with.
  5. Select Signer Certificates from the Personal/Signer Certificates list.
  6. Click Add.
  7. Select a data type from the Data type list, such as:
    Base64-encoded ASCII data
  8. Enter a certificate file name and location for the CA root digital certificate, or click Browse to select the name and location.
  9. Click OK.
  10. Enter a label for the CA root digital certificate, such as Test CA Root Certificate, and click OK. You are returned to the Key Management screen. The Signer Certificates field now shows the label of the CA root digital certificate you just added. You can either perform more tasks or exit the tool.