VOOZH about

URL: https://www.ibm.com/support/pages/node/667835

⇱ Enabling TLS for IBM Navigator for i


Enabling TLS for IBM Navigator for i

Troubleshooting


Problem

 Navigator for i does not come enabled for TLS by default. Navigator for i running on ADMIN1 can be enabled for TLS using these steps. Other servers can also use the wizard.

Environment

IBM i 7.3 and later
Navigator for i - ADMIN1 application server

Resolving The Problem

You are in: IBM i Technology Updates  > Navigator for i > Documentation on Functional Areas > Serviceability > Connection Properties > Enabling TLS for Navigator for i (TLS Connection)
Enabling TLS for Navigator for i:
There are two main steps to configuring and using secure connections for IBM Navigator for i:
  1. TLS Wizard - Configure TLS to use a secure port to the Admin1 server
  2. Enabling secure connections - Turn on secure connections so all connections between your GUI node and any managed node (including the managed node) will use TLS.
Connection Properties topics:

TLS Wizard
Navigator for i can be configured to use TLS using the Network -> Web Administration -> Application Servers -> ADMIN1 -> Configure TLS wizard in Navigator for i.  The Navigator for i application server Configure TLS wizard is now available with the IBM i HTTP group update approved in 2024.  IBM recommends utilizing the Navigator for i wizard to Configure or Re-configure your ADMINx application servers for TLS.  If Navigator for i is not available, another option is to execute the "Disable TLS" and "Configure TLS" wizards under Manage -> Application Servers -> ADMIN1 with the Heritage IBM Web Administration for i GUI using these steps.
Make sure you are running with the latest HTTP group PTF levels.  The following is a link to the preventative service planning page that shows the current levels:
http://www-01.ibm.com/support/docview.wss?uid=nas8N1021657#1
Navigator for i:
- Runs on the Admin1 HTTP server job using ports 2002 (Non-secure) and 2003 (with TLS configured)
- Non-TLS URL used to connect is http://hostName:2002/Navigator
- TLS URL is https://hostName:2003/Navigator
You can enable HTTPS by either using an existing certificate store or by using the Digital Certificate Manager *SYSTEM store.
Configure TLS to use a secure port

  • NOTE: To prevent a TLS warning regarding the certificate not being trusted in the browser, a certificate from a well-known Certificate Authority should be used.


Enabling Secure Connections
Turn on TLS Connections
Go to Servicability > Connection Properties and select the TLS Connection tab.
Test or set TLS Enablement.
Before non-secure ports are disabled, an administrator should turn on Global TLS by setting "Use TLS for All Users".  

[{"Type":"MASTER","Line of Business":{"code":"LOB68","label":"Power HW"},"Business Unit":{"code":"BU070","label":"IBM Infrastructure"},"Product":{"code":"SWG60","label":"IBM i"},"ARM Category":[{"code":"a8m0z0000000CH1AAM","label":"IBM Navigator for i"}],"ARM Case Number":"","Platform":[{"code":"PF012","label":"IBM i"}],"Version":"All Versions"}]

Was this topic helpful?

Document Information

Modified date:
11 November 2025

UID

nas8N1021834