Ask a Question

Advanced Search

Solution ID : SO22434

Last Modified : 05/31/2019

Managed PKI for SSL - Certificate Signing Request (CSR) Generation Instructions for IBM iSeries / AS400


This document provides instructions for generating a Certificate Signing Request (CSR) for IBM iSeries / AS400 server. If you are unable to use these instructions for your server, DigiCert recommends that you contact IBM.

NOTE: To generate a CSR, you will need to create a key pair for your server. These two items are a digital certificate key pair and cannot be separated. If you lose your public/private key file or your password and generate a new one, your SSL Certificate will no longer match.

To generate a Certificate Signing Request, perform following steps: 

  1. Start Digital Certificate Manager (DCM).
    NOTE: If you having problems with DCM refer to IBM iSeries Information Center
  2. In the navigation pane, select Create New Certificate Store
    NOTE: For renewal, select Select a Certificate Store > Manage Certificates > Renew Certificate > select certificate
    you want to renew > Renew
  3. Select *SYSTEM as your certificate store > Continue
  4. Select Yes to create a certificate as part of creating the *SYSTEM certificate store 
  5. Click Continue
  6. Select Symantec as the signer of the new certificate 
  7. Click Continue
  8. A form will display.  The information inputted into this form will display on your certificate.
    • Common Name: The fully-qualified domain name to which your certificate will be issued.
    • Organization: The full legal name of your company.
    • Organizational Unit: Use this field to differentiate between divisions within an organization.
    • City or Locality: Usually the city of your organization's main office, or a main office for your organization.
    • State or Province: Enter the full name of your state or province. 
      Note: Make sure the State or Province is not abbreviated (e.g. California).
    • Country: Enter the two-character abbreviation of country in which organization resides (e.g. US).
  9. Complete the form > click Continue
    NOTE:  Make sure to copy and paste the certificate signing request (CSR) file into a plain text editor and save.  If you close your window without saving, you will need to start over.
  10. Verify your CSR
  11. Proceed with Enrollment

Once the SSL certificate has been issued, follow the steps from this link to install it on the server: SO22436


          For more information refer to IBM Support