| BEA WebLogic 7 |
| Installing your Web Server Certificate |
Your certificate will be sent to you by email. The email message includes the
Web Server Certificate that you purchased in the body of the email message.
Copy the certificate from the body of the email and paste it into a text editor,
such as notepad to create text files.
Storing Private Keys, Digital
Certificates and Trusted Certificate Authorities
Once you have obtained private keys, digital certificates, and trusted certificate authorities, you need to store them so that WebLogic Server can use them to verify identity.
Digital certificates can only be stored in a file. Private keys can either be stored in a file or in a keystore accessed via the WebLogic Keystore provider. Trusted CA certificates can be stored in a file or in a JKS keystore. The keystore can be accessed via the WebLogic Keystore provider or specified on the command-line.
If you store the private keys, digital certificates, and trusted CA certificates in files, you need to set the SSL Server Key File Name, Server Certificate File Name, and Trusted CA File Name attributes in the WebLogic Server Administration Console.
For information about setting SSL attributes:
Setting Attributes for One-Way
SSL
If you store the private keys and trusted CA certificates in a keystore, you need to create a keystore and load the private keys and trusted CA certificates into the keystore. This release of WebLogic Server only supports JKS keystores.
For private keys, you must configure the WebLogic Keystore provider to point to the keystore, and set the SSL Server Private Key Alias and Server Private Key Passphrase attributes in the WebLogic Server Administration Console.
For trusted certificate authorities, you can either configure the WebLogic Keystore provider to point to the keystore, and set the Trusted CA File Name attribute in the WebLogic Server Administration Console or use the
Dweblogic.security.SSL.trustedCAkeystore command-line argument in the server start script to specify the keystore.
For more information, see:
Test your certificate by using a browser to connect to your server. Use the https protocol directive,
such as https://your.server.com/ to indicate you wish to use secure HTTP.
Please note that the padlock icon on your browser will be displayed in the locked position if your certificates are installed correctly and the server is properly configured for SSL.
Innovating Information Security
SupraLink, in partnership with GeoTrust, the leading provider of next
generation information security services, delivers secure e-commerce
transactions, identity verification and authentication solutions to
the global web community. SupraLink ensures a new level of
e-business security — your first step toward leveraging the full
business potential of the Internet.
|