IBM E02HRLL-G Administration Guide - Page 57

Configuring the certpath related properties, Configuring CRLDP

Page 57 highlights

1. In the Console, navigate to Profile > {Partner} > Certificate > Certificate Management 2. If you have logged in as a Hub Operator, then choose an internal partner and external partner. Make sure that both the values are not ″ALL″. 3. Click Search to filter partners or subset of partners. Note: The From and To packages are preloaded based on the partners. The subsets will also be displayed in the table based on your selection. The table columns have SSL client, Digital Signature (this will be disabled when the From partner is set to ″ALL″) and encryption (will be disabled if the To partner is set to ″ALL″. The rows have operation type). 4. Update the Certificate sets and click Save. The changes will be reflected at the connection level. Configuring the certpath related properties The certpath properties can be configured using the WebSphere Application Server admin console and the WebSphere Partner Gateway console. Access these properties by clicking System Configuration > DocMgr Configuration > Security. The properties are displayed using a read-only view. If you want to edit them, click the Edit icon. The following descriptions are brief summaries of the configuring process used with the certpath related properties. bcg.CRLDir This property contains the name of the directory where the CRLs are stored. The default value is: /common/security/crl bcg.checkRevocationStatus This property specifies if the revocation status is checked. The valid values for this property are true, false and blank. If the value is set to either true or blank, the revocation status of the digital certificates is checked. If the value is set to false, the revocation status is not checked. The default value and recommended setting of this property is true. bcg.build_complete_certpath This property specifies if the certpath is built to the root certificate or to the issuer certificate. The valid values for this property are true, false and blank. If the value is set to true or blank, the certpath is built to the root certificate. If the value is set to false, the certpath is built to the issuer certificate only. The default value and recommended setting of this property is true. Configuring CRLDP Configuring CRL DP (Certificate Revocation List Distribution Point) requires you to: v Set the Java Virtual Machine to enable or disable CRLDP v Set the HTTP proxy host and port Changing the Java Virtual Machine settings for CRLDP: Chapter 5. Account administration tasks 51

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268

1.
In the Console, navigate to
Profile
>
{Partner}
>
Certificate
>
Certificate
Management
2.
If you have logged in as a Hub Operator, then choose an internal partner and
external partner. Make sure that both the values are not
ALL
.
3.
Click
Search
to filter partners or subset of partners.
Note:
The
From
and
To
packages are preloaded based on the partners. The
subsets will also be displayed in the table based on your selection. The table
columns have SSL client, Digital Signature (this will be disabled when the
From
partner is set to
ALL
) and encryption (will be disabled if the
To
partner is set
to
ALL
. The rows have operation type).
4.
Update the Certificate sets and click
Save
. The changes will be reflected at the
connection level.
Configuring the certpath related properties
The certpath properties can be configured using the WebSphere Application Server
admin console and the WebSphere Partner Gateway console. Access these
properties by clicking
System Configuration
>
DocMgr Configuration
>
Security
.
The properties are displayed using a read-only view. If you want to edit them,
click the
Edit
icon. The following descriptions are brief summaries of the
configuring process used with the certpath related properties.
bcg.CRLDir
This property contains the name of the directory where the CRLs are
stored. The default value is:
<
WebSphere Partner Gateway Install Dir
>/common/security/crl
bcg.checkRevocationStatus
This property specifies if the revocation status is checked. The valid values
for this property are true, false and blank.
If the value is set to either true or blank, the revocation status of the digital
certificates is checked. If the value is set to false, the revocation status is
not checked.
The default value and recommended setting of this property is true.
bcg.build_complete_certpath
This property specifies if the certpath is built to the root certificate or to
the issuer certificate. The valid values for this property are true, false and
blank.
If the value is set to true or blank, the certpath is built to the root
certificate. If the value is set to false, the certpath is built to the issuer
certificate only.
The default value and recommended setting of this property is true.
Configuring CRLDP
Configuring CRL DP (Certificate Revocation List Distribution Point) requires you
to:
v
Set the Java Virtual Machine to enable or disable CRLDP
v
Set the HTTP proxy host and port
Changing the Java Virtual Machine settings for CRLDP:
Chapter 5. Account administration tasks
51