SSL Certificate Installation in IChain

iChain is an "End of Life" product that is no longer supported by Novell. It has been replaced by the Novell Access Manager.

Because iChain is an older product, it does not support installing multiple intermediate certificates through the Admin GUI. However, by following these instructions, you can install the certificate and configure it to send all the intermediate certificates that the clients may need to verify the certificate is valid.

Installing your Certificate in Novell IChain 2.2 or 2.3

  1. Extract the ZIP file containing the DigiCert signed certificate. You should have four certificate files:

    Server Certificate, e.g., www_domain_com.crt

  2. Download the DigiCert Trusted Root:

  3. In the iChain Admin GUI, click on Home -> Certificate Maintenance, and select the Certificate Name. The status of the certificate should be "CSR in process."

  4. Click on Store Certificate, then open the following certificate files with a text editor, and paste them in the appropriate fields:

    CA Certificate Contents = DigiCertHighAssuranceEVRootCA.crt (downloaded in Step 2)

    Intermediate Certificate Contents = DigiCertCA.crt (make sure the "Include intermeidate certificate" checkbox is checked)

    Server Certificate Contents = Server Certificate, ex. www_domain_com.crt

    Note: you will NOT paste the contents of DigiCertCA2.crt at this time. Hold on to it for later.

  5. Click on "Create" then "Apply." The certificate status should change to "Active."

  6. The certificate is now installed ready to be assigned to the accelerators.

Certificate Chain installation:

Note that these steps are only required if you received a DigiCertCA2.crt file.

  1. Open ConsoleOne and log into the Tree where the iChain Service Object is located.

  2. Locate and right-click on iChain's trusted root store, and click on "New" then "Object."

  3. Choose "NDSPKI: Trusted Root Object" and click "OK."

  4. Type in an NDS Object Name, such as DigiCertBridge," and Paste in the contents of DigiCertCA2.crt (or Read from File), and click "Finish."

  5. Open the iChain GUI, go to Configure -> Access Control, and click on "Refresh ACLCHECK."

    Wait about a minute, then you can check if the chain is correctly installed using the DigiCert SSL Checker Tool. Your DigiCert certificate files should now be installed and properly configured.

Installing your Certificate in older versions of Novell Ichain

  1. Download the Primary, Intermediate, and Root certificate files from your DigiCert account.

  2. You'll need to create a single SSL Certificate from the intermediate and root certificates. To do so, open a text editor (like NotePad), and paste in the contents of your intermediate certificate. Then paste in the contents of the root certificate. (In both cases, you must include the BEGIN and END tags.) Save this new certificate as DigiCertbundle.pem

  3. Now, go to ConsoleOne and open the ICS container for your iChain server, and open the certificate.

  4. Under the Certificates tab, click on Import. Then choose Read from File, and find the new DigiCertbundle.pem certificate you created.

  5. Hit Next. Choose Read from File, and browse to your DigiCert SSL certificate (your_domain_name.crt), then click Finish.

    If you get an error stating that the certificate's subject does not match the object's subject, do the following:

    Accept the certificate.

    On the iChain server click on Apply. This will install the certificate, but give you an error 1240. Now open the accelerator for the website you're securing. In the Certificate drop-down menu (in the Secure Exchange area), the certificate should be available. Select it, click OK and Apply.

    Refresh the Management display if it does not do so automatically. The site is now secured.

