i-effect Manual

Setting up SSL for ZendServer

Digital Certificate Manager

To call WebControl via the HTTPS protocol, an SSL certificate must be installed on the system.

The Digital Certificate Manager must be installed: 5770SS1, Option 34 (Digital Certificate Manager, part of the operating system)

Configure HTTP Server

Open the IBM Navigator for i at http://<SERVERNAME>:2001 and click on the link "IBM i task page".

image2020-5-4_14-39-20.png

On the next page open the link "IBM Web Administration for i: http" and log in with user name and password.

image2020-5-4_14-40-35.png


Under Administration -> HTTP Server, select the Apache version for your installed ZendServer (ZENDSVR6 - Apache or ZENDPHP7 - Apache) in the first dropdown and then the entry Virtual Host *:10080 or Virtual Host *:10090 in the second dropdown.

image2020-5-4_15-1-36.png


Then open the item "Security" on the left side.

image2020-5-4_15-19-9.png

Activate "SSL" in the drop-down menu and select the "Server Application ID" (QIBM_HTTP_SERVER_ZENDSVR6 or QIBM_HTTP_SERVER_ZENDPHP7).

You must also specify an HTTPS port. Take the port 10080 or 10090 used by Zend here.

Save the settings with the Apply button.

Set up certificates

Open the IBM Navigator for i at http://<SERVERNAME>:2001 and click on the link "IBM i task page".

On the next page open the link "Digital Certificate Manager: http" and log in with your username and password.


04.jpg


Now create a keystore for *SYSTEM

image2020-5-4_15-20-19.png

image2020-5-4_15-21-15.png

image2020-5-4_15-22-4.png

image2020-5-4_15-22-59.png

Or select it if it already exists.

image2020-5-4_15-23-53.png

Then import your certificate as server or client certificate. If your certificate depends on other certificates, you must first import these certificates as a certification authority.

image2020-5-4_15-25-20.png

image2020-5-4_15-33-10.png

image2020-5-4_15-26-47.png

image2020-5-4_15-30-21.png


Importing a Certification Authority CA

image2020-5-4_15-33-37.png

image2020-5-4_15-44-34.png


Assign certificate

Finally, under "Manage applications" -> "Reassign certificate", assign your certificate to the previously configured "Server application ID".

image2020-5-4_15-48-15.png

image2020-5-4_15-48-36.png

image2020-5-4_15-50-2.png

image2020-5-4_16-12-43.png

Restart ZendServer

Restart ZendServer and Apache. To do this, open the menu for your zendServer installation in the green screen with go zendsvr6/zsmenu or go zendphp7/zsmenu and select the following items in sequence:

  • 2nd End Zend Server Subsystem

  • 11 Stop Apache Server Instance

  • 1. start Zend Server subsystem

  • 10. start Apache Server Instance


You can now open WebControl with https://<SERVERNAME>:10080/webcontrol or https://<SERVERNAME>:10090/webcontrol