Operating Systems: i5/OS
Personalize the table of contents and search results
Configure certificate expiration monitoring
When certificates expire, they can no longer be used by the system.
WebSphere Application Server provides a utility to monitor certificates that
are close to expiration or have already expired. You can schedule certificate
monitoring, or you can request certificate monitoring on demand. You can also
configure options for deleting expired certificates and for recreating certificates.
WebSphere Application Server notifies you when a certificate is about
to expire. Complete the information required for notification messaging in Notifications.
Overview
Complete the following configuration steps in the administrative
console:
Procedure
- Click Security > SSL certificate and key management > Manage
certificate expiration.
- Type a number for the number of days threshold in the Expiration
notification threshold field. WebSphere Application Server
issues an expiration warning n number of days before expiration.
- Select or check one or more of the following options:
- Expiration check notification. Select the method from the list
that you want to use to receive your notification.
- Automatically replace expiring self-signed certificates. If
you do not want to recreate the self-signed certificate, clear the check box.
- Delete expiring certificates and signers after replacement.
If you do not want to delete the expired certificates and signers, clear the
check box.
- Enable checking. If you do not want to have certificate monitoring
enabled, clear the check box.
- Enter the time of day when you want certificate monitoring to take
place to schedule the running of the certificate expiration monitor.
- Select one of the following options:
- Check by calendar. For Weekday, enter the day of week
that you want to run the certificate expiration monitor. For Repeat Interval,
specify the frequency to run the certificate monitor.
- Check by number of days. Enter a number for how frequently
the monitor runs, in number of days.
- Click Apply.
Results
After completing the settings, a certificate expiration monitor object
and a schedule are set up in the configuration. The certificate expiration
monitor runs according to the configurations options that you configured.
What to do next
You can generate reports that state which certificates have expired.
The reports identify the notifications of certificate replacements and deletions.
The report is sent according to the notification option that you specified.
}
Manage certificate expiration settings
Notifications
Notifications settings
Related concepts
Certificate management
|