PositiveSSL Certificate Installation: Novell iChain

Installing your Certificate on Novell I-Chain

You will be receiving the following four files from comodo:
Root AddTrustExternalCARoot.crt
Intermediate CA UTNAddTrustServerCA.crt
Intermediate CA PositiveSSLCA.crt
domain/site certificate yourdomainname.crt
or You can download the Positive ssl Root and Intermediate files from here.

There are 2 possible views for installing your certificate, the alternative view is at the bottom of this page.

The first process is to create a combined file containing the intermediate and root certificates.

Open the PositiveSSLCA.crt in Notepad.
Use 'Edit-Select All' then 'Edit-Copy'.
Open a new text file with Notepad and paste the contents of the PositiveSSLCA.crt.Open the UTNAddTrustServerCA.crt in Notepad and Copy the entire contents.
Paste the contents of the UTNAddTrustServerCA.crt into the new text document AFTER theComodoUTNServerCA.crt.Open the AddTrustExternalCARoot.crt in Notepad and Copy the entire contents.
Paste the contents of the AddTrustExternalCARoot.crt into the new text document AFTER theUTNAddTrustServerCA.crt.Save the new combined certificate

OpenConsole ONE and open the ICS container for the iChain server.
Open the certificate.

Installing your Certificate on  Novell I-Chain

Installing your Certificate on  Novell I-Chain

Selectthe 'Certificates' tab and press the "Import" button.
Click 'Read from file' and browse to the combined certificate created previously.
Press 'Next'.
Click 'Read from file' and browse to the new server certificate or paste it into the window supplied.
Click 'Finish' to install the certificate.

You may get an error stating that the subject in the certificate does not match the subject in the object (CSR). This will be due to additionalOUs in the certificate. Accept the certificate anyway. If a validation is attempted on the certificate in Console ONE it will produce an error stating 'Unable to validate the certificate chain to a root certificate'.

On the iChain server click 'Apply'.
The certificate will be installed but will display an error stating '-1240 Certificate failed parsing -may need external certificate'.

Open the accelerator for the web site. The 'Certificate' drop down item in the Secure Exchange portion will now have the certificate available.Select the new certificate, click OK and then press 'Apply'.

When the Management display is refreshed the website will be secured with the new certificate.

Alternative View (Click image to enlarge)

Alternative View - Click to view Full Size

  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

PositiveSSL Certificate Installation: Apache & mod_ssl / OpenSSL

Installing your Certificate on Apache Mod_SSL / OpenSSLStep one: Copy your certificate to a...

PositiveSSL Certificate Installation: BEA Systems Weblogic

BEAWeblogic CertificateInstallation Instructions You will be receiving the following four...

PositiveSSL Certificate Installation: C2Net Stronghold

Installing a Certificate on a Stronghold Server Note:There are three certificates that need to...

PositiveSSL Certificate Installation: Cobalt RaQ 4 / 550 / XTR

Installing your Certificate on aCobalt RaQ4/XTR Installing the site certificate Goto the...

PositiveSSL Certificate Installation: Ensim

Installing your Certificate on Apache via Ensim Web appliance 3.1.xStep one: Loading the Site...