Question & Answer
Question
How do you convert the IBM Rational Host On-Demand (HOD) CustomizedCAs.p12 file to CustomizedCAs.jks file for support of Java Secure Socket Extension (JSSE) for Transport Layer Security (TLS) v1.0, v1.1 and v1.2?
Cause
The documention about How to configure Host On-Demand to use Java Secure Socket Extension for Transport Layer Security support states you can create a CustomizedCAs.jks file by converting the existing CustomizedCAs.p12 to JKS format. The documents that are referenced do not provide the instructions on how to do the conversion.
Answer
To convert the CustomizedCAs.p12 file to a jks file, follow these steps for each Host On-Demand server platform.
For Windows server
- Start the IBM Certificate Management utility
- Click Start
- Select Programs
- Select IBM Rational Host On-Demand
- Select Administration
- Select IBM Certificate Management
- Click on Key Database File on the menu bar
- Select Open
- Select PKCS12 for Key Database type
- Browse for your existing CustomizedCAs.p12 file.
- When prompted for password, enter hod.
- Click on Key Database File on the menu bar again.
- Select Save As.
- Select JKS for Key Database type.
- Enter the correct file name
- Verify the location is C:/Program Files (x86)/IBM/HostOnDemand/HOD or whatever your HOD publish directory is.
- Click OK.
- When prompted for the password, enter hodpwd.
- Click on Key Database File.
- Select Close.
For all platforms, including z/OS:
You can execute the following command from the HOD publish directory, ../hostondemand/HOD:
keytool -importkeystore -srckeystore CustomizedCAs.p12 -srcstoretype PKCS12 -destkeystore CustomizedCAs.jks -deststoretype JKS -deststorepass hodpwd
When prompted for the source keystore password, enter 'hod'.
NOTE: The Java level must be at 1.7.0 or higher.
Was this topic helpful?
Document Information
Modified date:
02 August 2018
UID
swg21697803