How To
Summary
This is a simplified document for pushing certificates from the Base ACS client to the ACS Windows Application Package.
Environment
Supported Windows OS's only.
Steps
Step 1
Open the ACS main GUI by double clicking on the Access Client Solutions Icon on your desktop.
The icon will appear as Figure 1 below.

Figure 1.
Step 2
Go to Help=>About.

Figure 2.
Step 3
Copy the java_home path from the Help=>About display.
This can be done easily by using your mouse to select the path and using the keyboard shortcut CTRL+C to copy the selected text.
Copy that text to windows Notepad or whatever your editor of choice is.
Then close the Help=>About Window.
NOTE: This step is not required if using IBM i ACS 1.1.9.8 or later as it is able to determine the path to Java_Home which will be shown in Step 7 below.

Figure 3.
Step 4
Open Key Management from Tools=>Key Management

Figure 4.
Step 5
Select all of the certificates in the list by clicking on the first certificate, then pressing the key combination of CTRL+A.
Once all of the certificates have been selected, continue to the next step.

Figure 5.
Step 6
Press the Push to Windows button when prompted. If prompted for a password, see Figure 6 below. Enter the password: ca400 and press the ok button. It is case sensitive, so type exactly as shown.

Figure 6.
Once you have entered the password, you'll see the certificates being copied. Once it stops and you see the DONE! text in the window, just press the OK button.

Figure 7.
Step 7
You should still have Key Management open.
Navigate to the menu item Key Database File and select Open.
NOTE: When using IBM i ACS 1.1.9.8 or later select the option for "Open Java default". When using this newer option, Steps 8 - 10 will be skipped.
NOTE: When using IBM i ACS 1.1.9.8 or later select the option for "Open Java default". When using this newer option, Steps 8 - 10 will be skipped.

Figure 8.
Step 8
You will use the path found in Step 3.
Browse to that location from the Open dialog.
You will see Files and Folders including a directory lib.

Figure 9.
Step 9
Double Click into the lib directory.
You will see a subfolder inside the lib directory called security. Double click into that directory as well.
Select the cacerts file within the security directory and press the Open button.

Figure 10.
Step 10
After pressing Open, you will be prompted for another password.
The password is changeit. This all one word and it is case sensitive. Enter exactly as shown and press OK.

Figure 11.
Step 11
Follow Step 5 through Step 6.
After those steps have been completed, close Key Management.
The IBM i Access Client Solutions Windows Application Package should be populated with your certificate(s) at this time.
Please Note:
IBM i ACS version 1.1.9.8 and above has enhanced Key Management.
This enhancement is a link from the Key Database File menu.
The link is named: Open Java Default.
This allows you to skip steps above 1-3 and 7-10.
It will directly open the Java key database.

Additional Information
The following link is to a full document regarding the topic of importing SSL/TLS certificates for use. This contains advanced topics, including managing certificates without the ACS Base client and automation topics:
Document Location
Worldwide
[{"Type":"MASTER","Line of Business":{"code":"LOB68","label":"Power HW"},"Business Unit":{"code":"BU070","label":"IBM Infrastructure"},"Product":{"code":"SSB2FY","label":"IBM i Access Family"},"ARM Category":[{"code":"a8m0z0000000CHZAA2","label":"Data Access"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]
Was this topic helpful?
Document Information
Modified date:
03 September 2025
UID
ibm17182818