JAY2068
December 10, 2018, 12:26pm
1
Anyone have any procedures or tutorials on how to change the self-signed certificate on the IBM AIX VIOS Intergrated Virtulization Manager web site?
I've googled till my fingers broke and most links take me to generic replacements for IBM products that I don't have.
Any help is appreciated. Thanks!
Neo
December 11, 2018, 7:14am
2
See IBM Ref, for a related hint:
IBM Knowledge Center - To replace the default certificate with a new self-signed certificat
To replace the default certificate with a new self-signed certificate, complete the following tasks:
Click New Self-Signed.
On the Create New Self-Signed Certificate page, enter a unique value in the Key Label field.
Provide values for the other fields, and click OK.
The list of Personal Certificates contains your new self-signed certificate and the certificate with the default label.
Select the certificate with the default label and click Rename.
Enter a new label for the certificate, and click OK.
Select the new certificate and click Rename.
Enter default as the new label, and click OK.
To replace the default certificate with a new certificate that is signed by an external certificate authority, complete the following tasks:
In the iKeyman utility, select Create > New Certificate Request.
Enter a unique value in the Key Label field and provide values for the other fields.
Pay special attention to the value you provide in the Enter the name of a file in which to store the certificate request field and click OK.
A message is displayed that informs you where the file that contains your new certificate request is located. The message tells you to send that new certificate request file to your external certificate authority.
On the Message page, click OK.
The external certificate authority signs your new certificate request and sends back your new certificate. The external certificate authority might send their signer certificate or the external certificate authority might assume that you already have their signer certificate in the key database file.
If the external certificate authority sends their signer certificate, complete the following tasks:
Select Signer Certificates and click Add.
Provide the File Name and Location values of the file that contains the Signer Certificate and click OK.
If the external certificate authority assumes that you already have their signer certificate in the key database file, complete the following tasks:
Select Signer Certificates and click Populate.
Search the lists of CA Certificates, select the one(s) for the external certificate authority that signed your new certificate request, and click OK.
If the lists of CA Certificates do not contain the one(s) for the external certificate authority that signed your new certificate request, ask your external certificate authority to send their signer certificate.
Once you have the signer certificate for the external certificate authority that signed your new certificate request, complete the following tasks:
Select Personal Certificates and click Receive.
Provide the File Name and Location values of the file that contains your new certificate and click OK.
Select the certificate with the default label and click Rename.
Enter a new label for the certificate and click OK.
Select your new certificate and click Rename.
Enter default as the new label and click OK.
In the iKeyman utility, click Key Database File > Exit.
Stop and start the Device, Alert, or Web server.
See also:
IBM Knowledge Center - Configuring a self-signed certificate
JAY2068
December 11, 2018, 10:17am
3
None of those links is what I have. I do not have "IBM Spectrum Control" available to me. I have a P8 with AIX installed with three LPARS the vios has a website that controls the LPAR's. It has a self signed cert. We need to put our own certificate on this.
The second link shows using '/opt/ibm/ccm/create_security_artifacts.sh' but that file is not found anywhere on my VIOS.
I think the keystore is here (not 100% sure): /usr/ios/lpm/gui/httpd/security/keystore/ibmjsse2.jks and .jts
Anyone have any idea on this?? I have searched an search. I can replace the ASMI cert with the web interface but the IVM site is self signed and I can't find any detail on updating it.