in our clm 6.0.3 setup plan, our applications (JTS,CCM,QM,RM,DNG,DM,DCC,LQE, JRS,RELM) need to be hosted in 9 different linux servers with bundled liberty profile.And also we have one IHS server in front of them.
So as per the installation process, we have installed these applications in 9 linux servers and installed IHS server.
In IHS Server
_
We created a kdb file and created a csr and raised the certificate request to CA.
Here we would need some more clarification on the below queries.
1) Once we got the Certificate from the CA, can we add the certificate to the IHS server kdb file (in personal certificate)
2) As per the installation guide, the next step will be making the ssl handshake with IHS and Liberty profiles. so we need to import the keystore of each liberty profiles (9 liberty profile here) to IHS keystore .
***But Here the customer needs mutual ssl authentication between all the application servers (eg: 1 application to all other 8 applications, for all and IHS also should be in mutual authentication.)along with IHS ( Means, IHS<->JTS<->CCM<->QM<->RM<->DNG<->DM<->DCC<->LQE<-> JRS<->RELM)
So we are planning to raise and get a Certificate from CA for each server using the liberty default key store and for IHS also by using the IHS kdb file. once we get the certificates for all 9 servers, and IHS,
a) first we will import the IHS SSL certificate to all 9 applications default keystore using ikeyman. (But in personal or Signer?)
b) from each applications, created certificates from CA, will import to all other applications keystore file ( is it in personal certificate or signer certificate?)
c) once all the applications key store are imported with other applications certificates. we will copy the updated keystore from each applications servers to IHS server and will Import to IHS kdb file for ssl authentication.
is this approach is correct or guide as for any changes need to be done ?
Comments
vowner owner
Feb 20 '18, 2:06 a.m.