Steps for installing the PKI Services CA certificate on a Microsoft Windows system

Perform the following steps to install the z/OS® PKI Services CA certificate in the correct location using Internet Explorer.

Before you begin

You need to know what version of Windows is running on your system.

Procedure

  1. On the Microsoft Windows system, start the Internet Explorer browser. In the address field, enter the URL for the PKI Services home page.

    _______________________________________________________________

  2. Click the link labeled "Install the CA Certificate to enable SSL sessions for PKI Services". Internet Explorer presents a "File Download - Security Warning" pop-up panel, asking whether to open or save the file, and indicating that the file is from the PKI Services system. For example, if the PKI Services system is alps4049.pok.ibm.com, the following information should be displayed in this pop-up panel:
    Type: Security Certificate, number bytes 
    From: alps4049.pok.ibm.com 
    Click Open.

    _______________________________________________________________

  3. Internet Explorer might display a pop-up panel to warn that a website wants to open web content using the browser. If it does, click Allow.

    _______________________________________________________________

  4. Internet Explorer presents a "Certificate" pop-up panel indicating that this CA Root certificate is not trusted, and to enable the trust, the certificate must be installed in the Trusted Root Certification Authorities store. Click Install Certificate.

    _______________________________________________________________

  5. Internet Explorer presents a " Certificate Import Wizard " welcome panel. Click Next >.

    _______________________________________________________________

  6. Internet Explorer displays the certificate store selections.
    1. If you are using Windows Vista and later versions of Windows, you must select Place all certificates in the following store and continue to step 7.
    2. If you are using Windows XP you can follow the instructions in step 6.a. Alternatively, you can select Automatically select the certificate store based on the type of certificate and click Next to have the wizard automatically select the certificate store. Then skip to step 8.

    _______________________________________________________________

  7. Internet Explorer presents a "Select Certificate Store" pop-up panel, allowing you to select the proper certificate store. Select the "Trusted Root Certification Authorities" item in the scrolled selection window, and click OK. Then click Next >.

    _______________________________________________________________

  8. Internet Explorer displays the "Completing the Certificate Import Wizard" panel. In the area labeled "You have specified the following settings:" the following information should be displayed:
    Certificate Store Selected By User       Trusted Root Certification Authorities   
    Content                                  Certificate  
    Click Finish.

    _______________________________________________________________

  9. Internet Explorer presents a "Security Warning" pop-up panel, indicating that a certificate is about to be installed, and asking you to verify that this is the intended action to take. Click Yes. Internet Explorer presents a confirmation pop-up, indicating that the certificate was successfully imported.

    _______________________________________________________________

Results

When you are done, you have successfully installed the PKI Services CA certificate, and your Windows system and Internet Explorer browser are ready to use the PKI Services web application.