6.5.26 IBM i

Configure RSE API access, profile authorities, and DCM application IDs

The (Beta) IBM i (AS/400) RSE API template imports the certificate into Digital Certificate Manager (DCM), assigns it to the specified applications, and restarts the affected IBM HTTP Server instances.

Run the CertKit agent on a separate host with HTTPS access to the IBM i Remote System Explorer (RSE) API. This beta template requires an RSA certificate.

Before you start

  • IBM i 7.3, 7.4, or 7.5 with DCM installed (5770-SS1 option 34).
  • A current HTTP Group PTF (IBM fix package) that includes the RSE Security Services APIs. The first PTFs with them were SI85819 (7.3), SI85818 (7.4), and SI85817 (7.5). Install the current PTFs that replace them.
  • The RSE API running in admin5 under the *ADMIN HTTP server, with HTTPS turned on (normally port 2012). To check, open https://your-ibmi:2012/openapi/ui/ and look for Security Services.
  • The agent machine can reach that HTTPS port.
  • CertKit agent 1.10.0 or later.

Template settings

  • IBM i RSE HTTPS URL: the address and port only, for example https://ibmi.example.com:2012. Don’t add /openapi/ui, a username, or a password.
  • IBM i user profile: use a dedicated profile with *ALLOBJ and *SECADM special authorities. To restart HTTP servers, it also needs authority to ENDTCPSVR and STRTCPSVR. The name can’t contain a colon.
  • *SYSTEM certificate store password: the password for DCM’s *SYSTEM certificate store.
  • Allow untrusted RSE TLS certificate: defaults to true, which skips validation of the RSE API’s HTTPS certificate. To enable validation, trust its issuing CA on the agent host and set this to false.
  • DCM application IDs: the applications that should use the certificate, separated by commas. An HTTP Server instance named MYSITE is QIBM_HTTP_SERVER_MYSITE. Each ID must already exist in DCM. The template won’t create it.

Restarts

HTTP Server restart mode controls what happens to the HTTP Server instances in your list:

  • stopstart (default): stops each instance, then starts it again.
  • restart: restarts each instance with STRTCPSVR SERVER(*HTTP) RESTART(*HTTP).
  • none: assigns the certificate only. You restart the instances yourself.

Instances that are already stopped stay stopped.

Restart these services manually after deployment. The job output lists them under ACTION REQUIRED:

  • *ADMIN, if you listed QIBM_HTTP_SERVER_ADMIN. The RSE API runs inside it, so CertKit won’t stop it.
  • Applications that aren’t HTTP Servers, such as host servers.

Old certificates

Old certificates stay in *SYSTEM after each renewal. Their labels start with certkit-. Delete them in DCM once no application uses them.

Common problems

  • “RSE DCM Security Services are unavailable or rejected the *SYSTEM store credentials”: check DCM option 34, *ALLOBJ and *SECADM on the profile, the store password, and that the HTTP Group PTF is current.
  • “RSE server preflight failed”: check that the RSE API is running, HTTPS is on, the port is right, and the agent machine can reach it. If Allow untrusted RSE TLS certificate is false, the agent may not trust the IBM i’s certificate.
  • “DCM application definition … was not found”: check the ID’s spelling in DCM.
  • “Could not confirm an existing RSA certificate”: DCM says the certificate is already there, but CertKit can’t match it to this certificate. Check the *SYSTEM labels in DCM. Nothing was deleted or assigned.
  • “RSE accepted the assignment … but neither … could confirm it”: check the application in DCM before you try again. Changes DCM already accepted are not undone.
  • “HTTP Server … did not start within 90 seconds”: check the instance’s job log. HTP8351 usually means a bad certificate or CA chain.
  • “HTTP Server … did not end within 180 seconds”: check WRKACTJOB SBS(QHTTPSVR) and restart the instance yourself.
  • “supports RSA certificates only”: the certificate doesn’t use an RSA key. Reissue it as RSA.