The IBM WebSphere Server must first be installed and configured as a web container before you configure it with the AMSDK in SSL. For installation instructions, see the WebSphere server documentation. To configure WebLogic as a web container for Access Manager, see Chapter 2, Access Manager 7.1 Configuration Scripts.
Start ikeyman.sh, located in the Websphere /bin directory.
From the Signer menu, import the certification authority’s (CA) certificate.
From the Personal Certs menu, generate the CSR.
Retrieve the certificate created in the previous step.
Select Personal Certificates and import the server certificate.
From the WebSphere console, change the default SSL settings and select the ciphers.
Set the default IBM JSSE SSL provider.
Enter the following command to import the Root CA certificate from the file you just created into application server JVM Keystore:
$ appserver_root-dir/java/bin/ keytool -import -trustcacerts -alias cmscacert -keystore ../jre/lib/security/cacerts -file /full_path_cacert_filename.txt
app-server-root-dir is the root directory for the application server and full_path_cacert_filename.txt is the full path to the file containing the certificate.
In Access Manager, update the following parameters in AmConfig.properties to use JSSE:
com.sun.identity.jss.donotInstallAtHighestPriority=true com.iplanet.security.SecureRandomFactoryImpl=com.iplanet. am.util.SecureRandomFactoryImpl com.iplanet.security.SSLSocketFactorImpl=netscape.ldap.factory. JSSESocketFactory com.iplanet.security.encyptor=com.iplanet.services.unil.JCEEncryption
Configure Access Manager in SSL Mode. For more information, see Configuring Access Manager in SSL Mode.