Before you begin: this procedure changes the web server's TLS configuration. Back up
httpd.confand the key database, plan a suitable restart window and test the change outside production first. The certificate and its private key must already exist in an IBM HTTP Server key database.
IBM HTTP Server uses the term SSL in its configuration directives, although the resulting HTTPS connection should use the TLS protocols allowed by your current security policy. This procedure enables HTTPS on port 443 for a Maximo web server and can redirect existing HTTP requests to it.
The paths, host name and certificate label below are examples. Replace them with values from your environment.
Configure the HTTPS virtual host
Open the IBM HTTP Server configuration file. On Windows, its default location is beneath the installation root:
<IHS_INSTALL_ROOT>\conf\httpd.confAdd or enable the following configuration:
LoadModule ibm_ssl_module modules/mod_ibm_ssl.so
Listen 0.0.0.0:443
<VirtualHost *:443>
ServerName maximodomain.com
SSLEnable
KeyFile "E:/IBM/HTTPServer/key.kdb"
SSLServerCert newkey
</VirtualHost>
SSLDisableChange these example values:
maximodomain.comis the DNS name clients use to reach Maximo. It must match a name covered by the server certificate.E:/IBM/HTTPServer/key.kdbis the key database containing the personal certificate and its private key. The IBM HTTP Server service account must be able to read it.newkeyis the certificate label in that key database. OmitSSLServerCertonly when you intend IBM HTTP Server to use the certificate marked as the key database's default.
The remaining directives provide the structure of the configuration:
LoadModuleloads IBM HTTP Server's SSL module.Listenaccepts connections on the standard HTTPS port.SSLEnableenables HTTPS inside this virtual host.SSLDisablekeeps SSL disabled for configuration outside the virtual host.
IBM documents the available options and scopes in its SSL directive reference. In particular, the KeyFile path must identify a valid key database and the SSLServerCert value must match a certificate label in it.
Validate the configuration using the configuration-check command supplied with your IBM HTTP Server version. Resolve any errors before restarting the IBM HTTP Server service. After the restart, confirm that Maximo opens successfully at its https:// address and inspect the IBM HTTP Server error log for TLS or certificate errors.
Redirect HTTP traffic to HTTPS
Once HTTPS works correctly, you can redirect requests received on port 80. Ensure the rewrite module is loaded; in a standard configuration this line might already exist but be commented out:
LoadModule rewrite_module modules/mod_rewrite.soAdd these rules outside the SSL virtual host:
RewriteEngine On
RewriteCond %{SERVER_PORT} =80
RewriteRule ^(.*)$ https://%{SERVER_NAME}%{REQUEST_URI} [R,L]This retains the original request path while moving the request to HTTPS. IBM also documents mod_rewrite as a way to rewrite HTTP requests to HTTPS.
Restart IBM HTTP Server, then request Maximo over http:// and confirm that the browser is redirected to the corresponding https:// URL. Check other applications served by the same IBM HTTP Server because a global rewrite rule affects them too.
Redirect the site root to Maximo
If the server is dedicated to Maximo, you can also redirect the root URL to the Maximo context path:
RedirectMatch ^/$ /maximo/With both redirects enabled, a request for http://maximodomain.com ends at https://maximodomain.com/maximo/. Restart IBM HTTP Server after changing the configuration, then test the root URL, the Maximo URL and any other context paths the server hosts.