BPM, Workflow, and Case

 View Only

 BAW - ICN SSL certificates exchange

Kean Hoong Yong's profile image
Kean Hoong Yong posted Thu March 06, 2025 10:02 PM

Hi all,

I need some guidance on this issue of my. I am setting up a Proof of concept machine for BAW with external ICN/CE, I am following the IBM BAW installation guide and everything was OK until now. When I tried to access the BAW from the external Navigator's browser, I am getting a screen saying the BAW refused to connect.

The BAW WAS keystore personal certificate is already in Navigator WAS truststore signer and Navigator WAS keystore personal certificate in BAW WAS truststore signer as per the installation instructed in step 5:

Configuring single sign-on with LTPA for an external IBM Business Automation Navigator - IBM Documentation

The LTPA SSO on both servers is working fine. The Navigator WAS systemout.log showing certificate_unknown, I suspected that something not right with the mutual SSL authentication. I have no idea what have I did wrong or did not do, been trying to figure out but still have no success. Wonder if anyone can help. Both servers are using Websphere build-in self-signed certificate.

Below are my enivornment:

BAW Server (baw.mydomain.local)

Windows server 2019 with AD
Websphere application server ND 8.5.5

Navigator server (ce55.mydomain.local)
Windows server 2019 standalone, not joinning any Active direcory
Websphere application server 9.0

Attached here are the screenshots for the errors and the SSL truststore/keystore.

Rgds

Yong

Chuck Abernathy's profile image
Chuck Abernathy

Please check your BAW plugins URL's configured in Content Navigator.  Are they configured for SSL? 

you can also use the Browser Developer tools(network) while accessing your BAW client to see why or were it's having an issue.