IBM i Security and Vulnerabilities User Group

IBM i Security and Innovation

Join this online user group to communicate across IBM i Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Digital Certificate Manager Functionality

    Posted Tue October 15, 2024 10:42 AM

    Hello,

    I'm fairly new to the administrative side of the IBM i, so I hope I'm asking a question in the right group. My predecessor passed away suddenly and we have limited documentation on a great deal of the system. I have a CA certificate in DCM that is about to expire and my belief is that it is not in use currently. What method(s) can I use to confirm that it is not in use and can safely be disabled? I haven't been able to find any documentation on this topic.

    Thanks in advance for your help and patience!



    ------------------------------
    Craig Mardis
    ------------------------------


  • 2.  RE: Digital Certificate Manager Functionality
    Best Answer

    Posted Tue October 15, 2024 04:33 PM
    Edited by Craig Mardis Wed October 16, 2024 05:47 PM

    Hello Craig,

    When you login to Digital Certificate Manager(DCM) please select the *SYSTEM store . As soon as you are in screen will be presented with all the certificates available there (active + expired). Every certificate itself has a "view" option which will show you "Application Definitions" which are using this certificate. 

    Another option is to select "Manage Application Definitions" after signing on to *SYSTEM store. Here you will see all the application definitions with the certificate assigned to it. 

    Let me know if it helps. 



    ------------------------------
    Rohit Chauhan
    Senior Technical Specialist
    Norway
    ------------------------------



  • 3.  RE: Digital Certificate Manager Functionality

    Posted Tue October 15, 2024 04:50 PM

    Rohit,

    Thanks very much for your response! I did check all the Application Definitions and the Certificate which will expire is not listed on any of the Application Definitions. Also, no applications are listed when I click  the "view" option on the certificate, there are no applications listed. So if it is not listed on any of these definitions that means that it's not in use on the system at all? Is that correct?



    ------------------------------
    Craig Mardis
    ------------------------------



  • 4.  RE: Digital Certificate Manager Functionality

    Posted Tue October 15, 2024 05:32 PM

    Hello Craig,

    That's correct. If it is not assigned to any of the application definitions then it is not in use. 



    ------------------------------
    Rohit Chauhan
    Senior Technical Specialist
    Norway
    ------------------------------



  • 5.  RE: Digital Certificate Manager Functionality

    Posted Wed October 16, 2024 09:17 AM

    Wonderful! Thank you!



    ------------------------------
    Craig Mardis
    ------------------------------



  • 6.  RE: Digital Certificate Manager Functionality

    Posted Wed October 16, 2024 05:49 PM
    Done! Thanks again!


    Craig Mardis
    The Taylor Group, Inc.
    Direct: (662) 736-9376
    Internal Extension: 9376