The Novell Appliance ships with a self-signed digital certificate. Instead of using this self-signed certificate, you should use a trusted server certificate that is signed by a trusted certificate authority (CA) such as VeriSign or Equifax.
The certificate works for both the Novell Appliance and the iPrint software (ports 9443 and 8443). You do not need to update your certificate when you update the iPrint Appliance software.
Complete the following sections to change the digital certificate for your Novell Appliance. You can use the digital certificate tool to create your own certificate and then have it signed by a CA, or you can use an existing certificate and key pair if you have one that you want to use.
On the Digital Certificates page, select the certificate that you just created, then click
> > .Complete the process of emailing your digital certificate to a certificate authority (CA), such as Verisign.
The CA takes your Certificate Signing Request (CSR) and generates an official certificate based on the information in the CSR. The CA then mails the new certificate and certificate chain back to you.
After you have received the official certificate and certificate chain from the CA:
Revisit the Digital Certificates page by clicking
from the Novell Appliance.Click
> > . Browse and select the trusted certificate chain that you received from the CA, then click .Select the self-signed certificate, then click
> > .Browse to and upload the official certificate to be used to update the certificate information.
On the Digital Certificates page, the name in the
column for your certificate changes to the name of the CA that stamped your certificate.Activate the certificate, as described in Section 9.4.3, Activating the Certificate.
When you use an existing certificate and key pair, use a .P12 key pair format.
Go to the Digital Certificates page by clicking
from the Novell Appliance.On the Digital Certificates page, in the Key Store drop-down menu, select
.Click
> > . Browse and select your existing certificate, then click .Click Step 3, then click .
> > . Browse and select your existing certificate chain for the certificate that you selected inClick
> > , then browse to and select your .P12 key pair file, specify your password if needed, then click .Continue with Section 9.4.3, Activating the Certificate.
On the Digital Certificates page, in the
drop-down menu, select .Select the certificate that you want to make active, click
, then click .Verify that the certificate and the certificate chain were created correctly by selecting the certificate, then clicking
.NOTE:When you activate a certificate, the
button might still be enabled for that certificate. You can ignore it, as it does not affect the certificate activation.All certificates that are included with the IBM Java package that is bundled with the version of SLES that iPrint Appliance ships with, are installed when you install iPrint Appliance.
You can use the Digital Certificates tool on the iPrint Appliance to remove certificates that are not used by your organization, if you are concerned about keeping them.
Also, you can use the Digital Certificates tool on the iPrint Appliance to maintain the certificate store by removing certificates that have expired and then installing new certificates as needed, according to your organization’s security policies.
To access the Digital Certificates tool:
Click
from the Novell Appliance.iPrint Appliance uses only the certificates that relate to LDAP and SMTP. In the
drop-down menu, under , a self-signed certificate is displayed. This certificate is required for iPrint Appliance, and must not be deleted.In the
drop-down menu, under , you can delete all the certificates except the certificate, and any other LDAP or SMTP certificates that you might have imported.