← WebSphere Administration
05 / 6 · 40 MIN

TLS and administrative access

Locate effective trust and apply privileges proportionate to the task.

Concept and mechanism

An SSL configuration references identity and trust material. A keystore can contain the private key and personal certificate used by the local identity; a truststore contains signers trusted by the client. The same application can participate in inbound and outbound paths with different selections. An accessible HTTPS frontend does not establish that the JVM trusts a partner certificate. Before changing stores, identify the endpoint, handshake error, presented chain, and configuration actually selected. A specific configuration may not use the cell truststore you just changed. Do not replace this investigation with repeated imports into several stores without traceability.

Guided application

Retrieve from port can obtain certificate information, including fingerprint, issuer, and validity. Compare it with the expected identity and change before trusting it. An expired certificate remains expired after import: the endpoint must present valid material and an appropriate chain. During a fictional CA rotation, coordinate with the partner, validate the path, and document recovery. In the console, distinguish viewing, operation, and configuration changes. With administrative security enabled, Monitor matches viewing needs; granting Administrator to simplify viewing exposes unnecessary operations. Handover should identify who can inspect, stop, or change services and how temporary access is removed. Trust and authorization decisions should be established in the scope actually used.

IN PRACTICE

Outbound calls fail after CA rotation: inspect the application SSL configuration, not only the IHS certificate.

Common pitfalls

Import as renewal; connectivity as identity; inbound success as proof of outbound trust.

Related topics: ND topology and effective configuration · Deployment, routing, and state · JDBC, pools, and transaction outcomes

Take this idea with you

Validate identity, SSL selection, and effective privilege before concluding.

Create account

Reference: SSL configuration and truststore selection · DR WebSphere traditional ND 9.0.5; maintenance baseline 9.0.5.29 (2026-09-08); documentation reviewed 2026-09-30