How To
Summary
Network communication between each component of Workload Automation (WA) is
secured using TLS v1.2 and v1.3 protocols. This is accomplished by deploying TLS Certificates
for each component. WA deploys Self-Signed certificates at installation time to make it
easy to deploy and have a working scheduling environment with little effort. To enhance
security, organizations decide to replace the default certificates with commercially recognized
CA (Certificate Authority) signed certificate for each server in the environment. This requires
all default self-signed certificates used by every component to be replaced by CA signed
certificates.
In order to keep the environments intact and all components communicating while the default
certificates are replaced, instead of a rip and replace approach, a cap and grow approach is
adopted where the default certificates coexist with the new certificates until the new certificates
have been imported into the KeyStores and TrustStores of all components. The default
certificates can then be deleted from all KeyStores and TrustStores.
The following sections describe the procedure to replace the certificates.
Document Location
Worldwide
Log InLog in to view more of this document
Was this topic helpful?
Document Information
Modified date:
04 June 2026
UID
ibm17159522