DataPower

DataPower

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

Can Datapower crypto tool be used to create a certificates with additional SANs?

  • 1.  Can Datapower crypto tool be used to create a certificates with additional SANs?

    Posted Thu November 16, 2023 05:23 AM

    Hi,

    My question is if I need to generate a certificate outside of Datapower when I e.g. need multiple SAN?

    Or is there a way to use the Datapower crypto tool for this?

    Regards,
    Rikard Almroth
    Epical



    ------------------------------
    Rikard Almroth
    ------------------------------


  • 2.  RE: Can Datapower crypto tool be used to create a certificates with additional SANs?

    Posted Thu November 16, 2023 10:19 AM

    So, yes, you can generate a certificate to be used outside of DataPower using the Crypto Tools.  You have to be sure to check the "Export Private Key".

    At this point, though, it can get complicated.  Is your certificate going to be self-signed, or are you going to send a CSR out to a signing authority?  Generally speaking, when you go through a signing authority, you can present the various SANs there.   Otherwise, you'll still have to manipulate the self-signed certificate after the fact to insert the SANs, and (IMHO), if you have to go that far, you might as well use something like OpenSSL to handle the process, as it would be less tedious.



    ------------------------------
    Joseph Morgan
    ------------------------------