Difference between revisions of "Information Systems:Renewing the Web Orders SSL Certificate"
Jump to navigation
Jump to search
Line 29: | Line 29: | ||
# Choose “Server or client” and click continue |
# Choose “Server or client” and click continue |
||
# The renewed certificate file from the CA needs to be copied to the IFS, /temp works well |
# The renewed certificate file from the CA needs to be copied to the IFS, /temp works well |
||
− | # Type the file |
+ | # Type the file path into the import screen and click continue |
+ | # Assign the NEW certificate to the correct application which should be either Web Orders or InfoNet at the bottom of the list |
||
# Specify the same friendly label as you chose in step 16 and click continue |
# Specify the same friendly label as you chose in step 16 and click continue |
||
# If you get an error that validation of the certificate failed then the CA’s root certificates also need to be imported in the correct order so that the renewed certificate can be validated all the way up the chain by going back to step 26 and choosing CA instead of server |
# If you get an error that validation of the certificate failed then the CA’s root certificates also need to be imported in the correct order so that the renewed certificate can be validated all the way up the chain by going back to step 26 and choosing CA instead of server |
Revision as of 13:20, 6 May 2019
Instructions On How To Renew An SSL Certificate For Web order Or InfoNet These instructions were written by DarrenF on January 11 2016 and describe what needs to be done when the SSL certificate on a website hosted on the Power8 needs to be renewed. Hopefully this all happens before the current expiry date.
- Go to https://bart.unipharm.local:2005/ibm/console - No as of 2019 use Web Navigator instead
- Ignore unsupported browser message
- Login with credentials – probably all object auth or qsec
- On left side IBM I Management panel, at the bottom, click on “Internet Configurations”
- Then click on “Digital Certificate Manager” in the main tab
- Log in again with same credentials
- On the left side, click on “Select A Certificate Store”
- Choose *SYSTEM and click continue
- Enter in the password which is visionit and click continue
- Click the triangle twisty next to “Manage Certificates” and then click “View Certificate”
- Write down the friendly name of the certificate that needs to be renewed because there may be duplicates from past years – make sure that you renew the correct certificate by checking the expiry date!
- Click “Renew Certificate” in the “Manage Certificate” menu
- Select the correct certificate that needs to be renewed and click the Renew button
- The next screen should only have 1 option as an Internet Certificate Authority, click continue
- Choose “Yes – Create a new key pair” and click continue
- The “New Certificate Label” is the friendly name for this renewal – try and make the label descriptive and unique
- Key size must be 2048
- Fill out the rest of the fields underneath Certificate Information and take a screenshot of that screen
- Country code is CA and then click continue
- Copy the certificate request into Notepad and save the file – be sure to copy from the first dash line to the end of the last dash line
- Click OK
- Take the saved block of text and provide that to the CA reseller when purchasing the renewed certificate
- Try and buy a renewed certificate for the longest period of time possible unless the website or server doing the hosting is going to be decommissioned
- If using Network Solutions they will do an email and phone validation on the SSL renewal to make sure that the certificate is going to the correct company
- When the CA has issued the renewed certificate, download it
- On the Digital Certificate Manager website, on the left side click “Import Certificate” from the “Manage Certificates” menu
- Choose “Server or client” and click continue
- The renewed certificate file from the CA needs to be copied to the IFS, /temp works well
- Type the file path into the import screen and click continue
- Assign the NEW certificate to the correct application which should be either Web Orders or InfoNet at the bottom of the list
- Specify the same friendly label as you chose in step 16 and click continue
- If you get an error that validation of the certificate failed then the CA’s root certificates also need to be imported in the correct order so that the renewed certificate can be validated all the way up the chain by going back to step 26 and choosing CA instead of server
- Click on “Assign Certificate” from the “Manage Certificates” menu
- Choose the newly renewed certificate you just imported and click “Assign to Application”
- Either InfoNet or Web Orders should be at the bottom of the list, put a check mark in the right application and click REPLACE
- Delete the files that were put on the IFS as they are not needed anymore
- Log out of the Digital Certificate Manager page and the web Navigator site
- At this point you could stop the IBM HTTP server and then restart it to see the renewed certificate immediately – otherwise you will have to wait for the EOD to automatically bounce the web server instances
- Check in a web browser that the new certificate with the correct expiry dates is actually being used
- Profit