3.2 Creating an SSL Connection Between Access Manager and Secure API Manager

To establish an SSL connection between Secure API Manager and Access Manager you must export the Access Manager trusted root certificate and then import the trusted root certificate to the appliance that will host the Database Service component.

Ensure that you import the Access Manager trusted root certificate before you deploy a Database Service component. The Deployment Manager copies the Access Manager trusted root certificate to each component when it deploys the component. If you do not import the Access Manager trusted root certificate, the Deployment Manager does not work properly. NetIQ wants to ensure that all communication between Secure API Manager and Access Manager is over SSL to avoid any security issues.

3.2.1 Exporting the Access Manager Trusted Root Certificate

Ensure that you import the Access Manager trusted root certificate before you deploy a Database Service component. The Deployment Manager copies the Access Manager trusted root certificate to each component when it deploys the component. If you do not import the Access Manager trusted root certificate, the Deployment Manager does not work properly. NetIQ wants to ensure that all communication between Secure API Manager and Access Manager is over SSL to avoid any security issues.

To export the Access Manager trusted root certificate:

  1. Log in to the Access Manager administration console.

  2. Click Security > Trusted Roots.

  3. Click the name of the trusted root certificate named configCA.

  4. Click Export Public Certificate > DER File.

    Access Manager automatically downloads the certificate.

  5. Ensure that you can access this certificate from the appliance that will run the Database Service component.

3.2.2 Importing the Access Manager Trusted Root Certificate

After you have obtained a copy of the Access Manager trusted root certificate in the DER format, you must import the certificate to the appliance that will run the Database Service component.

To import the Access Manager trusted root certificate:

  1. Log in to the appliance management console for the appliance that will become the first Database Service component using the root user and password that you set during the deployment of the appliance. For more information, see Deploying the Secure API Manager Appliances.

    https://ip-address-or-dns-name-appliance:9443
  2. Click Digital Certificates.

  3. In the Key Store field, select Custom Application Certificates.

  4. Click File > Import > Trusted Certificate.

  5. Click Browse and browse to and select the Access Manager trusted root certificate, then click Open.

  6. Click OK.

  7. In the toolbar, click Home, then click Reboot to reboot the appliance.

The reboot adds the Access Manager certificate to the appliance’s key store. At this point, you can finish the integration with Secure API Manager and Access Manager in the Deployment Manager. For more information, see Completing the Integration Between Secure API Manager and Access Manager.