Configuring the SSL connection protocol for the network
About this task
To configure SSL for your network, perform the following
steps:
- Create an SSL directory under the
TWA_homedirectory. By default, the pathTWA_home\TWS\sslis registered in thelocaloptsfile. If you create a directory with a name different from ssl in theTWA_homedirectory, then update thelocaloptsfile accordingly. - Copy
openssl.cnfandopenssl.exeto the SSL directory - Create as many private keys, certificates, and Trusted CA lists as you plan to use in your network.
- For each workstation that will use SSL authentication:
- Update its definition in the IBM Workload Scheduler database with the SSL attributes.
- Add the SSL local options in the localopts file.
In IBM Workload Scheduler, SSL support is available for the fault-tolerant agents only (including the master and the domain managers), but not for the extended agents. If you want to use SSL authentication for a workstation that runs an extended agent, you must specify this parameter in the definition of the host workstation of the extended agent.