Contact us at |support@ssldragon.com
  • install an ssl certificate on ibm http server

How to install an SSL Certificate on IBM HTTP server?

Thursday, March 14th, 2019

This guide provides step by step instructions on how to generate a CSR code and install an SSL Certificate on IBM HTTP server. After you complete the SSL installation, keep reading to discover a few interesting tidbits about IBM’s history. Finally, at the end of this article, we reveal the best place to shop for SSL Certificates for your IBM server.

If you’ve already generated your CSR code, you can jump straight to the installation instructions. For faster navigation, use the links below.

Generate a CSR Code on IBM HTTP Server
Generate a CSR Code on IBM Domino Server
Install an SSL Certificate on IBM HTTP Server
Install an SSL Certificate on IBM Domino Server
Test your SSL installation
IBM servers’ history versions
Where to buy the best SSL Certificate for IBM HTTP servers?

Generate a CSR Code on IBM HTTP Server

The Certificate Signing Request (CSR) is a piece of encoded text containing your contact information. To apply for an SSL Certificate, you must create your CSR code and then send it to your CA for validation. Along with the CSR you will also generate your private key, an essential element of your SSL Certificate. You will need the private key during the installation process.

To generate your CSR code and private key for the IBM HTTP server, we’ll use the IKEYMAN utility. Please, follow the steps below:

Generate the Key Data Base (.kdb) file

  1. On your Windows system, go to Start > Programs > IBM HTTP Server > Start Key Management Utility
  2. From the Menu pane, choose Key Database File, then click New
  3. In the File Name field, enter a name for your new Key Database file
  4. In the Location field, specify the directory in which you wish to save the .kdb file
  5. Create a password for your Key Database file, the check the Stash the password to the file box
  6. Click OK.

Generate the CSR code

  1. Open your newly created Key Database file using the IKEYMAN utility
  2. Locate the Key database content section, and click the down arrow to expand the list options, then select Personal Certificates Request
  3. Fill in the required info as shown below:
    • Key Label: give your SSL cert an easy-to-remember name. For instance, your website’s name
    • Key Size: 2048
    • Common Name: enter the FQDN (fully-qualified domain name) you want to secure. For example, yourdomain.com
    • Organization: specify the full, legal name of your company. For instance, GPI Holding LLC
    • Organization unit: name the department managing your SSL Certificate. Usually, it’s IT or Web Administration
    • Locality: write the full name of the city where your company is located. For example, San Diego
    • State/Province: enter the full name of the state or region where your company is registered. For instance, California
    • Country: type the two-letter code of your country. For example, US. You can find all the country codes here
    • Certificate request file name: enter a name for the file, or use the default name
  4. Save the new .arm file in the same directory as the Key Database file
  5. You can open your CSR file with any text editor including Notepad and copy-paste its contents during the SSL order process with your vendor.

Generate a CSR code on IBM Domino

  1. Log into your Domino Administration client and double-click on Server Certificate Administration
  2. Select Create Key Ring option
  3. If prompted, enter a name and password for your key ring. Next, choose 2048 bits for your key size
  4. Now, submit the following details:
    • Common Name: your FQDN (fully-qualified domain name) to which you want to assign the SSL Certificate. For example, yourdomain.com
    • Organization: the full, legal name of your organization (e.g., GPI Holding LLC)
    • Organizational Unit: name the department requesting the SSL Certificate (e.g., It, Web Administration, etc.)
    • City or Locality: provide the city where of your headquarters. For instance, Seattle
    • State or Province: type the state where your company is located. For example, Washington
    • Country: you can find your country-code here.
  5. Verify the info you’ve just entered, and click Continue to create your key ring file
  6. In the next window, select Create Certificate Request and, under Method, choose Paste intro form on CA’s site
  7. That’s it. Now, you can copy and paste the CSR code, including the header and footer tags into your online SSL order on SSL Dragon’s website.

Install an SSL Certificate on IBM HTTP server

After you successfully pass the SSL validation and receive the necessary SSL files in your inbox, proceed to the installation.

Prepare your SSL certificate files:

From the ZIP archive, extract the following files:

  • The root certificate
  • The intermediate certificate
  • The primary certificate

Install the Root and Intermediate certificates

  1. Enter the IKEYMAN from the UNIX command prompt. Launch the Key Management Utility on your Windows system in the IBM HTTP Server folder
  2. In the main UI, select Key Database File, then Open
  3. Select your key database and hit OK
  4. Enter your password and click OK
  5. In the Key Database section, select Signed Certificates then click Add
  6. Select the Certificate you want to add, then OK. First, add the root certificate, then the intermediate one.

Install the Primary SSL Certificate

  1. Go to IKEYMAN > Key Database > Personal Certificates and click Receive
  2. Select your primary SSL Certificate (your_domain.crt) and hit OK.

Congratulations, you’ve completed the SSL installation on your IBM HTTP server.

Install an SSL Certificate on IBM Domino

To Install an SSL certificate on the IBM Domino server, you need to combine all your SSL certificate files into the same Key Ring that you used during CSR (Certificate Signing Request) generation.

Make sure you have the following files:

  • The root certificate
  • The intermediate certificate
  • The primary certificate
  1. In your Domino Admin Panel, go to the system database, and locate the Domino Server Certificate Administrator (CERTSRV.NSF) file
  2. Click Install Trusted Root Certificate into Key Ring, and write the file name of the Key Ring that you created during the CSR generation
  3. Select one of the three available options to upload your root certificate. The easiest way is to browse the file location
  4. Click Merge Certificate into Key Ring
  5. Repeat steps 2,3 and 4 for your intermediate certificate
  6. Now, click on Install certificate into Key Ring and enter your Key Ring file name (the one that you created while generating the CSR)
  7. Specify the path of your primary certificate and click Merge certificate into Key Ring.

Congratulations, you have successfully installed an SSL Certificate on your IBM Domino web server.

Test your SSL installation

After you install an SSL Certificate on IBM HTTP server, it’s recommended to run a diagnostic test on your SSL configuration, to ensure that no SSL errors affect your site’s performance. With the help of these high-end SSL tools, you can get instant scans and reports on your SSL Certificate.

IBM HTTP Servers’ history and versions

International Business Machines Corporation (IBM) is an American multinational information technology company founded by Charles Ranlett Flint in 1911. Nicknamed Big Blue, IBM is one of the world’s largest employers with over 380,000 employees.

IBM HTTP Server (IHS) is a web server that runs on the Apache Software Foundation’s HTTP Server. It is available for download and use free of charge but without IBM support.

Here are the latest IBM HTTP Server releases:

  • IBM HTTP Server 9.0.0 released on 11 Mar 2016 (Apache 2.4.12 based)
  • IBM HTTP Server 8.5 released on 15 June 2012 (Apache 2.2.8 based)
  • IBM HTTP Server 8.08 released on 17 June 2011 (Apache 2.2.8 based)

IBM Notes (formerly Lotus Notes) and IBM Domino (formerly Lotus Domino) are a collaborative client-server software platform offered by IBM.

First released in 1989, IBM Domino is written in Java and CC+, and runs on Windows, OS X and Linux operating Systems.

Below are the latest IBM Notes/Domino versions:

  • IBM Notes/Domino 10.01 released on December 18, 2018
  • IBM Notes/Domino 10.0 released on October 10, 2018
  • IBM Notes/Domino 9.0 released on 21 March, 2013
  • IBM Notes/Domino 8.5.x released from December 2008 to December 2013

Where to buy the best SSL Certificate for IBM HTTP servers?

If you’re searching for affordable SSL Certificates, then SSL Dragon is your best SSL vendor. Our fast and user-friendly website will guide you through the entire range of SSL Certificates. All our products are signed by trusted Certificate Authorities and are compatible with IBM HTTP servers. We offer the following SSL validation types:

We bring you the best prices on the market and stellar customer support for any certificate you buy. And, if your struggling to find the perfect cert for your project, our SSL Wizard and Advanced Certificate Filter tools will give you quick suggestions.

If you find any inaccuracies, or you have details to add to these SSL installation instructions, please feel free to send us your feedback at [email protected]. Your input would be greatly appreciated! Thank you.