IBM i Global

IBM i 

A space for professionals working with IBM’s integrated OS for Power systems to exchange ideas, ask questions, and share expertise on topics like RPG and COBOL development, application modernization, open source integration, system administration, and business continuity.


#Power


#IBMi
#Power
 View Only
  • 1.  IBM DCM -assign and/or replace Certificate

    Posted Tue February 14, 2023 05:00 AM

    We are using certificate for securing the services/servers.
    Are there any thoughts of cautions when assigning/replacing certificate?
    Can this be done "online" when users are working? 
    What about restarting the servers so the new certificate is used?
    Or is there any servers that need to be restarted?



    ------------------------------
    Erik Aasland
    IBMi administrator
    Fremtind Insurance
    ------------------------------


  • 2.  RE: IBM DCM -assign and/or replace Certificate

    Posted Tue February 14, 2023 06:51 AM
    Edited by Satid Singkorapoom Tue February 14, 2023 07:24 AM

    Dear Erik

    If my faint memory serves, I remember a past post last year in this group about this and I remember that the poster said he had to restart any server(s) that use certificate to enable the new certificate to take effect. I'm fairly certain the replacement can be done on-line. If I can find that thread, I will post it here. 

    Find it: https://community.ibm.com/community/user/power/discussion/certificates-and-ssl

    There are two different IBM Technote on using IBM i DCM for different OS releases :

    https://www.ibm.com/support/pages/digital-certificate-manager-dcm-frequently-asked-questions-and-common-tasks

    https://www.ibm.com/support/pages/digital-certificate-manager-i-dcm-frequently-asked-questions-and-common-tasks


    ------------------------------
    Education is not the learning of facts but the training of the mind to think. -- Albert Einstein.
    ------------------------------
    Satid S.
    ------------------------------



  • 3.  RE: IBM DCM -assign and/or replace Certificate
    Best Answer

    Posted Wed February 15, 2023 02:19 AM
    Edited by Erik Aasland Tue February 21, 2023 07:46 AM

    Hi *ALL,

    I found at https://www.ibm.com/support/pages/renewing-third-party-ssl-certificate-digital-certificate-manager-dcm

    11. Assign the new certificate to whatever applications you would like to secure. Note: Some applications may need to be restarted for the change to take effect

    I'm not sure what those "some app" are but many times I have replaced certificates (TELNET, FTP, ...) without restart the service ... 


    ------------------------------
    Fernando Plaza
    IBM i System Administrator
    CD INVEST
    MADRID
    ------------------------------



  • 4.  RE: IBM DCM -assign and/or replace Certificate

    Posted Tue February 21, 2023 07:49 AM

    Hi
    Most of the applications did not need to restart.
    But for some like ssh and so on it needed a IPL or a restart of the applcation.



    ------------------------------
    Erik Aasland
    IBMi administrator
    Fremtind Insurance
    ------------------------------