IBM i Global

 View Only

 ACS with SSL implementation

Jump to  Best Answer
Mohamed Nabil Berriri's profile image
Mohamed Nabil Berriri posted 05/14/26 06:01 AM

Hello,

We are testing the SSL implementation on ACS and we need to automate the integration of corporate root CA without having a dialogue box confirmation during the handshake.

Is there an automated way to integrate the root CA with command line instead of GUI certificate integration in JKS store?

Note: We used keytool and the cert is successfully integrated but closing ACS totally and during execution of SSL connection again, the store is become blank and root CA trust dialogue box back again.

Thank you very much,

Nabil

Robert Berendt's profile image
Robert Berendt IBM Champions  Best Answer
Dave Charron's profile image
Dave Charron

Section 9.1 of the Getting Started document lists supported command-line options.

9.1.3 Certdl

/PLUGIN=certdl  /SYSTEM=<system>
Trusts the certificate authority certificates received by verifying an SSL connection to the specified system.
This is required for server authentication with SSL.
See section 9.1.11 Ping for more details on the services that are checked.
Krister Karlsson's profile image
Krister Karlsson IBM Champions

Another approach would be to create and populate the ACS cacerts keystore file with the corporate root CA and deploy the cacerts file with ACS together with an modified AcsConfig.properties.

In AcsConfig.properties you can point to where the cacerts file exist with the directive com.ibm.iaccess.CertFile 

Sylvain Manceau's profile image
Sylvain Manceau

Also, there is a graphical tool in ACS for keystores & certificates management, look for "Key Management" in Tools menu.