Skip to Main Content
Integration


This is an IBM Automation portal for Integration products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.


Status Future consideration
Workspace DataPower Gateway
Created by Guest
Created on Jul 2, 2019

A tool to check if a certificate is actually being used

Would it be possible to have a tool or command which can query whether a certificate which is on the file system of a device is actually being used? Or to put it another way would it be possible to query what certificate is being used by a service at a point in time?

Idea priority High
RFE ID 134296
RFE URL
RFE Product IBM DataPower Gateways
  • Guest
    Reply
    |
    Jul 3, 2019

    This might be well known but I add it for completeness.
    - There's no easy way to find unused certificate files. You have to compare the list of configured certificate objects with the list of files.
    - There's kind of a brute force method to figure out whether a Crypto Certificate object is in use - try to delete it.
    - There's a softer but potentially cumbersome way to find dependencies. Use the Object Status (up / services), expand the view and look for certificate objects.

    In general it would really be helpful to have a dependency view on a particular object e.g. as an additional “Used by” action on each object.

  • Guest
    Reply
    |
    Jul 2, 2019

    It seems like if you did an export before the upgrade of the certificate and an export after, you could see in both export files which objects reference the old/new certificate by grepping the log file, no?

  • Guest
    Reply
    |
    Jul 2, 2019

    You can easily do this by exporting the domain (or all domains) and search the export.xml for the file namne of the certificate. That will give you the object(s) where it is used. If you don't find the file namne (other than in the section) it is not being used...

  • Guest
    Reply
    |
    Jul 2, 2019

    You can easily do this by exporting the domain (or all domains) and search the export.xml for the file namne of the certificate. That will give you the object(s) where it is used. If you don't find the file namne (other than in the section) it is not being used...