IBM Support

How to Create the Local Certificate Authority (CA) Store in Digital Certificate Manager for i (DCM)

Troubleshooting


Problem

This document describes the process to create the Local Certificate Authority (CA) store in Digital Certificate Manager for i (DCM).

Resolving The Problem

This document describes the process to create the Local Certificate Authority (CA) store in Digital Certificate Manager for i (DCM).

This is a short document to describe the steps required to create the Local Certificate Authority (CA) store in Digital Certificate Manager for i (DCM). If you are having trouble getting to the DCM page, try your IBM i system name or IP address and typing the URL:

http://<IBM i name or IP address>:2006/dcm/mainframe/home

or

https://<IBM i name or IP address>:2007/dcm/mainframe/home
    • Step 1



      Click Create Certificate Store followed by Local CA:

      image-20220823082903-1

      image-20220823083059-3

    •  
    • Step 2



      On the next screen, you will need to provide a password to the Local Certificate Authority store and click Create. This Local CA store is used to create Certificate Authorities to digitally sign local SSL certificates:

      image-20220823083358-4

    •  
    • Step 3



      On the next screen, you will create the Local CA certificate by clicking Create:

      image-20220823083928-6


      image-20220823084939-7

      Note: Fill out all the required fields in the form(identified with a red X image-20220823090648-2). You may also want to change the Key Size and the Validity Period of Certificate Authority (CA):

      Key Size: This determines the length of the encryption key (choose between RSA 1024, 2048, and 4096 ECDSA 256, 384 and 521). The default is 1024, but this might not be considered a large enough key size for some security compliance. In this case, you might want to use 2048 or 4096.

      Validity period of Certificate Authority (CA): This is the number of days that the CA certificate will be valid for, once this limit is reached the certificate expires and will need to be renewed (7300 days is the maximum value for this parameter)

    •  
    • Step 4



      You may want to set the Policy Data for the Local CA. This policy determines how long server or client SSL certificates that are signed by the Local CA certificate will last 

      image-20220823085333-8
      image-20220823085632-9
      This defaults to 365 days and the maximum you can set this to 2000. This determines how often the server/client certificates created by the CA will be valid. Once finished making selections click Change. You have now successfully created the Local CA store and Local CA certificate. 

    •  
    •  

    [{"Type":"MASTER","Line of Business":{"code":"LOB57","label":"Power"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SWG60","label":"IBM i"},"ARM Category":[{"code":"a8m0z0000000CISAA2","label":"Digital Certificate Manager"},{"code":"a8m0z0000000CSxAAM","label":"Digital Certificate Manager-\u003EFAQs"}],"ARM Case Number":"","Platform":[{"code":"PF012","label":"IBM i"}],"Version":"7.3.0;7.4.0;7.5.0"}]

    Historical Number

    677938735

    Document Information

    Modified date:
    08 September 2022

    UID

    ibm16614757