Contact us at |support@ssldragon.com
  • install an ssl certificate on oracle

How to install an SSL Certificate on Oracle Servers?

Wednesday, March 13th, 2019

In this extensive, step by step guide you will learn how to generate a CSR code and install an SSL Certificate on Oracle servers and apps. This tutorial offers CSR generation and SSL installation instructions for the following platforms:

  • Oracle Wallet Manager
  • Oracle iPlanet Web Server
  • Oracle WebLogic Server

Besides configuration information, in the latter parts of this guide, we also offer a brief overview of Oracle’s history, as well as useful tips on where to buy the best SSL Certificate for your Oracle-based platform. Use the links below to navigate to the section of your interest.

Contents:

Generate a CSR Code on Oracle Wallet Manager
Generate a CSR Code on Oracle iPlanet Web Server
Generate a CSR Code on Oracle WebLogic Servers
Install an SSL Certificate on Oracle Wallet Manager
Install an SSL Certificate on Oracle iPlanet Web Server
Install an SSL Certificate on Oracle WebLogic Server
Test your SSL installation
Oracle servers’ history and versions
Where to buy the best SSL Certificate for Oracle Servers?

Generate a CSR code on Oracle Wallet Manager

To create your CSR (Certificate Signing Request) on Oracle Wallet Manager, please follow the steps below:

  1. In the Oracle Wallet Manager, from the main menu select Operations, then click Create Certificate Request
  2. In the newly opened window, provide the required information:
    • Common Name: enter the FQDN (fully-qualified domain name) you want to protect with an SSL Certificate. For example, yourdomain.com

      Note: Oracle Wallet Manager does not support wildcard certificate installation.

    • Organizational Unit: name the department within your company in charge of web security. Usually, it’s IT or Web Administration. For a Domain Validation cert, put NA instead
    • Organization: specify the full name of your company. For instance, GPI Holding LLC. If you have a Domain Validation certificate, type NA instead
    • Locality/City: write the full name of the city where your company is legally registered. For example, Seattle
    • State/Province: type the full name of the state/province where your company is located. For example, Washington
    • Country: from the drop-down list, select your country
    • Key Size: select 2048 bits
  3. Double check the information you’ve just submitted, then click OK
  4. A new window will confirm the successful CSR generation
  5. Back in the Oracle Manager Wallet, go to Operations and click Export Certificate Request
  6. Save the CSR on your device by providing a name for the file, and then clicking OK
  7. Now, you can open your CSR code with any text editor of your choice such as Notepad, and copy-paste its contents into the required field during your SSL application process.

Generate a CSR Code on Oracle iPlanet Web Server

Please, follow the instructions below to generate a CSR code on Oracle iPlanet Web Server:

  1. In your Oracle dashboard, click Server Certificates and then Request
  2. From the Configuration list, select a configuration for which you want to install the SSL Certificate
  3. Next, select the token (Cryptographic Device), which contains the keys
  4. If your key is stored on the server, pick Internal. If it resides on an external device, select the name of the external token from the drop-down menu. Provide a password for the token you’ve selected
  5. Submit the required details as shown below:
    • Server Name: provide the FQDN (fully-qualified domain name) you want to secure. For instance, yourwebsite.com. If you have a wildcard certificate, add an asterisk in front of the domain name (e.g., *.yourwebsite.com)
    • Organization: write the official, legal name of your company. For example, GPI Holding LLC
    • Organizational Unit: name the department responsible for SSL management. It could be IT or Web Administration
    • Locality: specify the city where your organization is located
    • State or Province: enter the state where your organization is registered
    • Country: provide the two-letter abbreviation of your country name (in ISO format). For example, US for the United States. You can find more country codes here.
  6. For the key type, select RSA, 2048 bits
  7. For the Certificate Signing Authority (CSA) select CA Signed
  8. Verify the info you’ve just entered and then click Generate Request then Finish
  9. Copy your newly generated CSR code including the header and footer contents into a text document such as Notepad, and click the Close button.

That’s it! Now you can use your CSR during the order process with your SSL vendor.

Generate a CSR Code on Oracle WebLogic Server

You’ll be creating your CSR code using Java Keytool. First, you will generate a new Keystore file, and then create your own Java Keytool commands to generate a CSR code for your Oracle WebLogic Server.

Note: For a smooth and error-free SSL installation, we recommend you create a new Keystore before you generate the CSR.

Create a new Keystore

  1. Run the following command to create a new Keystore:
    keytool -genkey -alias server -keyalg RSA -keystore your_domain.jks
    Replace your_domain with the actual domain name you want to secure.

    Note: If you have a wildcard certificate, DO NOT include an asterisk (*) in the file name. This character is not supported.

  2. They Keytool will prompt you to enter the following details for your SSL Certificate:
    • Your first and last name: do not type your first and last names. Instead, enter the domain name to which you want to assign your SSL Certificate. For example, yourdomain.com
    • Name of your organizational unit: enter the department in charge of web security. Usually, it’s Web Administration or IT
    • Name of your organization: specify your legal business name. For instance, GPI Holding LLC. If your official company name contains symbols such as & or @ you must spell them out, or omit completely
    • Name of your City or Locality: provide the full name of the city where your business is registered. For instance, San Francisco
    • Name of your State or Province: enter the full name of the state or region where your company is located
    • The two-letter country code for this unit: write the two-letter code of your country. For example, US. For more country-codes, visit this link
    • When asked to verify your details: type Y or YES to confirm
    • Password: you’ll need to create a password for your Keystore. Store it in a safe location, or password manager. You’ll need it during the CSR generation and SSL installation.

Generate a CSR Code from your Keystore

  1. In the Keytool, run the following command:
    keytool -certreq -alias server -keyalg RSA -file your_domain.csr -keystore your_domain.jks
    Replace your_domain attribute with the actual domain name you want to secure.
  2. When prompted, enter the password you’ve created for your keystore
  3. It’s done. Your CSR code is now ready
  4. Back up your Keystore file in a safe location
  5. Now, you can open your_domain.csr file with any text editor of your choice (e.g., Notepad) and copy-paste its contents including the —–BEGIN NEW CERTIFICATE REQUEST—– and —–END NEW CERTIFICATE REQUEST—– when ordering your SSL Certificate.

Install an SSL Certificate on Oracle Wallet Manager

The instructions below will walk you through the installation process:

  1. Download and extract your SSL certificate files from the ZIP folder that your CA sent you. You should have the following files (.crt extension) on your device or desktop:
    • Root CA certificate
    • Intermediate Certificate
    • Primary Certificate
  2. Go to Oracle Wallet Manager and click Wallet, then Open
  3. Select Operations > Imported Trusted Certificate
  4. Now, import your Root CA certificate from the directory in which it resides on your device. Click OK
  5. Next, perform the same action for your Intermediate CA Certificate. Go to Operations> Import Trusted Certificate, and upload your intermediate cert. Click OK
  6. Finally, navigate again to Operations> Import Trusted Certificate, and import your primary SSL Certificate. Click OK
  7. After installation, in the navigation menu, the certificate node will change from Certificate: [Requested] to Certificate: [Ready].

Congratulations! You’ve successfully installed an SSL Certificate on Oracle Wallet Manager. Test your SSL installation for potential errors and vulnerabilities.

Install an SSL Certificate on Oracle iPlanet Web Server

After the CA sends you all the necessary SSL files to your inbox, you can continue with the certificate installation.

  1. In your Oracle iPlanet Server click on Server Certificates tab then Install
  2. From the Configuration list, select a Configuration for which you need to install the certificate
  3. Next, select the Token (Cryptographic Device) containing the keys. If your key is stored internally, on your server, choose the Internal option. Otherwise, choose the name of the external token from the drop-down menu. Provide the password for the token you selected
  4. Paste your SSL Certificate contents in the corresponding box. Make sure you copy-paste the whole text, including —–BEGIN NEW CERTIFICATE REQUEST—– and —–END NEW CERTIFICATE REQUEST—– tags.
  5. Alternatively, you click browse and import your certificate file manually
  6. Next, provide a nickname for your SSL Certificate. You can enter your website’s name or any other name of your liking
  7. From the available list of handling secure requests, choose the HTTP Listener.

Congratulations, you’ve successfully added an SSL Certificate to your Oracle iPlanet Web Server.

Install an SSL certificate on Oracle WebLogic Server

  1. Open each SSL file with a text editor such as Notepad, and copy its contents into a separate file. Make sure you merge your root, intermediate and primary certificates into a single file, and save it in the .pem format. For instance, yourcertificte.pem
  2. Import yourcertificate.pem file using the Java Keytool. Run the following command:
    keytool -import -alias [alias_name] -file [yourCertificate].pem -keystore /path_to_keystore[keystore_name].jks

Configure your WebLogic server to use the SSL Certificate

  1. Log into your WebLogic server admin console, and, under Domain Structure, expand Environment, then Servers node
  2. Select the server name you want to configure, then go to Configuration and select the Keystores tab
  3. Next, under Change Center, click Lock & Edit
  4. From Identity and Trust Locations, choose Keystores
  5. Now, specify the fully-qualified path to custom Identity, Trust KeyStore
  6. On the Keystores page, enter a custom Passphrase for Identity and Trust KeyStore. Click Save
  7. In the WebLogic Server Console, got to the SSL section, and, under the Configuration tab, specify the proprieties of your Private Key Alias and Passphrase. Click Save
  8. Finally, go to General and check the SSL Listen Port Enabled box. In the Change Center, click Activate Changes

Congratulations, now you know how to install an SSL Certificate on Oracle WebLogic.

Test Your SSL Installation

After you install an SSL Certificate on Oracle server or app, it’s imperative to check your configuration for potential errors or vulnerabilities. You can do this efficiently with the help of high-end SSL tools. Pick software from the linked article, to get instant scans and reports on your SSL Certificate.

Oracle server history and versions

Oracle Corporation is an American company specializing in enterprise software and cloud computing. In 2018, Oracle registered the third largest revenue in the software making industry, behind Microsoft and Alphabet.

Founded on June 16, 1977, by Larry Ellison, Bob Miner, and Ed Oates, as Software Development Laboratories (SDL), the company adopted its current name in 1995.

Oracle produces both software and hardware products, as well as offering complimentary services. Its large portfolio includes databases, middleware, applications, enterprise management, cloud computing, operating systems, and hardware.

Listed below are the latest releases of popular Oracle products such as Oracle Wallet Manager, Oracle iPlanet Web Server, Oracle WebLogic Server.

Oracle Wallet Manager

  • Current release: 11g Release 1 (11.1)
  • Oracle Wallet Manager is backward-compatible to Release 8.1.7.

Oracle iPlanet Web Server

  • Oracle iPlanet Web Server 7.0.27 (released 2018-03)
  • Oracle iPlanet Web Server 7.0.26 (released 2017-04)
  • Oracle iPlanet Web Server 7.0.9.

Oracle WebLogic Server

  • WebLogic Server 12cR2 (12.2.1.3) – August 30, 2017
  • WebLogic Server 12cR2 (12.2.1.2) – October 19, 2016
  • WebLogic Server 12cR2 (12.2.1.1) – June 21, 2016
  • WebLogic Server 12cR2 (12.2.1.0) – October 23, 2015
  • WebLogic Server 12cR1 (12.1.3) – June 26, 2014
  • WebLogic Server 12cR1 (12.1.2) – July 11, 2013
  • WebLogic Server 12cR1 (12.1.1) – Dec 1, 2011

Where to buy the best SSL Certificate for Oracle Servers?

SSL dragon is your one-stop place for all your SSL needs. We offer the lowest prices on the market for the entire range of our SSL products. We’ve partnered with the best SSL brands in the industry to offer you high-end SSL security and dedicated support. All our SSL certificates are compatible with Oracle servers. Here are the SSL certificate types you can buy from us:

To help you select the perfect SSL certificate, we created a couple of handy SSL tools. Our SSL Wizard can recommend the best SSL deal for your online project, while the Certificate Filter, can help you sort and compare different SSL certificates by price, validation, and features.

If you find any inaccuracies, or you have details to add to these SSL installation instructions, please feel free to send us your feedback at [email protected]. Your input would be greatly appreciated! Thank you.