← Integrations

Automated SSL certificate renewal for IBM i (AS/400)

DCM won't install a renewed certificate on its own. CertKit will.

On IBM i (still AS400 in our hearts), certificates live in the Digital Certificate Manager *SYSTEM store and are assigned to each application by ID. A renewed certificate does nothing until someone imports it, reassigns every application, and restarts the servers that use it. Every 47 days.

CertKit issues and renews the certificate centrally, then the CertKit Agent imports it into DCM through IBM's own RSE API, assigns it, and restarts your HTTP Server instances. Nothing is installed on the IBM i.

Start free trial Watch demo

Built for IBM i Beta

The pre-built IBM i template ships in your CertKit account. No scripting required.

On every renewal, the agent imports the certificate and its CA chain into *SYSTEM, assigns it to the DCM application IDs you list, and stops and starts each HTTP Server instance so it loads the new certificate.

HTTP Server restarts take a few seconds per instance, so schedule them in a deployment window. Applications that aren't HTTP Server, like host servers, are assigned but left for you to restart.

How to install an SSL certificate in IBM i Digital Certificate Manager

The manual process, if you want to do it yourself:

  1. Get the certificate as a PKCS#12 file. Create a certificate request in DCM, or bring your own key and package it. DCM rejects the AES-encrypted PKCS#12 that OpenSSL 3 makes by default as an "unsupported encryption type", so export with legacy 3DES.
  2. Import the CA certificates. Open DCM, select the *SYSTEM certificate store, and import each missing intermediate and root under Manage Certificates → Import certificate → Certificate Authority (CA).
  3. Import the server certificate. Same menu, as a Server or client certificate. Labels must be unique, so each renewal needs a new label.
  4. Assign it to each application. Under Manage Applications → Update certificate assignment, point every application ID at the new label, like QIBM_HTTP_SERVER_MYSITE for an HTTP Server instance.
  5. Restart and clean up. Applications only read the assignment at startup. Restart each HTTP Server instance, then delete the old certificate once nothing uses it.

Every one of these steps is manual, and DCM won't repeat any of them when the certificate renews. With lifetimes shrinking to 47 days, that's twelve times a year, for every application ID on every system. Miss one and the web front end on your system of record stops serving HTTPS.

At 47 days, automation is the only sustainable way to run IBM i certificates. Here's how CertKit does it.

How it works

 Your network            CertKit                 ACME CA
┌───────────────────┐     ┌──────────────────┐    ┌─────────────┐
│  ┌─────────────┐  │     │                  │    │             │
│  │Deploy Agent │◄─┼─────┤  Issue & Renew   │◄──►│             │
│  └──┬────┬─────┘  │     │   Certificates   │    │             │
│     │    │RSE API │     │                ┌───┐  └─────────────┘
│     │    │ :2012  │     └───────────┬────│DNS│
│     ▼    ▼        │                 │    └───┘
│ ┌──────────────┐  │                 │
│ │ IBM i DCM    │  │                 │
│ │ [x] Imported │  │                 │
│ │ [x] Assigned │  │ ◄───────────────┘
│ │ [x] Restarted│  │       Verify
│ └──────────────┘  │
└───────────────────┘

CertKit issues and renews certificates centrally using delegated DNS validation. You create a one-time CNAME record, and CertKit handles every ACME challenge after that.

The agent runs on a Windows server inside your network. It pulls each renewal from CertKit over outbound HTTPS, then calls the RSE Security Services API on the IBM i. The IBM i never talks to CertKit, never runs ACME, and never holds DNS credentials.

From an operational perspective, CertKit is easy to deploy and manage. The ability to configure unique and specialized certificates is key to replacing our manual certificate processes.

Laura Thomas, Senior Central Systems Administrator, University of St. Thomas

What CertKit handles

Setup takes about ten minutes

  1. Connect your domain. Add a one-time CNAME record to delegate DNS validation to CertKit.
  2. Prepare the IBM i. Confirm the RSE API is running with Security Services at https://your-ibmi:2012/openapi/ui/, and create a dedicated profile with *ALLOBJ and *SECADM.
  3. Install the CertKit Agent. One command on a Windows server that can reach the IBM i on port 2012.
  4. Add the IBM i deployment script. Enter the RSE URL, the profile, the *SYSTEM store password, and your application IDs. Use an RSA certificate.

See the full architecture →

IBM i deployment requirements and troubleshooting →

Why not renew in DCM?

DCM's Renew option only creates a new certificate request. You still take it to a CA, wait, import the result, reassign it, and restart. Getting an ACME client onto the IBM i itself means open-source packages in PASE and DNS credentials on your system of record.

CertKit keeps all of that off the box. The agent uses the API IBM already ships, so there's nothing to install or maintain on the IBM i.

IBM i is just one part of your stack

The systems around it need certificates too: Java servers like Tomcat and Oracle WebLogic, integration platforms like Boomi, file transfer servers like CrushFTP, and Windows databases like SQL Server. CertKit automates all of it from one account.

See all integrations

Start automating IBM i certificates today

Free 90-day trial. No credit card required. Direct access to our engineering team to get you set up.

Start free trial See pricing