IBM Support

Renew a X509 Certificate that will expire

Question & Answer


Question

An X509 certificate in use by IBM Sterling Connect:Direct will expire, how do you renew it?

Answer


1. Start Secure+ tool, open local node record and make a note of the key certificate location.



2. Use the OpenSSL utility on Unix or Windows and issue the following command, replacing “keycert.txt” with path to the key certificate file above and enter the private key password when prompted.



3. Check the contents of the generated CSR.txt look similar to below:



4. If details are correct send the file to your Certificate Authority for signing.

5. When you receive the new Certificate from the CA, you should edit your Key Certificate file and replace the existing certificate details with the new certificate but leaving the same private key in place. The order of private key and the certificate does not matter.



6. When the CA sends you the certificate, they may also send you an additional set of CA root certificates; you should distribute these to your partners as they may be different from the ones that signed your original certificate.

[{"Product":{"code":"SSRRVY","label":"IBM Sterling Connect:Direct for Microsoft Windows"},"Business Unit":{"code":"BU055","label":"Cognitive Applications"},"Component":"--","Platform":[{"code":"PF033","label":"Windows"}],"Version":"4.6","Edition":"","Line of Business":{"code":"LOB59","label":"Sustainability Software"}},{"Product":{"code":"SSKTYY","label":"IBM Sterling Connect:Direct for UNIX"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":" ","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"}],"Version":"4.1","Edition":"","Line of Business":{"code":"LOB59","label":"Sustainability Software"}}]

Document Information

Modified date:
24 July 2020

UID

swg21987318