ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » General Discussion » CSQX620E & RC=-36 SSL problem

Post new topic  Reply to topic
 CSQX620E & RC=-36 SSL problem « View previous topic :: View next topic » 
Author Message
plebel
PostPosted: Thu Jun 05, 2008 10:48 am    Post subject: CSQX620E & RC=-36 SSL problem Reply with quote

Newbie

Joined: 05 Jun 2008
Posts: 2

z/OS 1.7 with IBM WebSphere MQ for z/OS V5.3.1
Microsoft Window Server 2003 with IBM WebSphere MQ 5.3

Good afternoon.
We are trying to set up SSL channels between a z/OS Queue manager and a Windows queue manager. We have read the information in IBM Redbook "WebSphere msg broker and SSL" and the WebSphere MQ Security book V5.3 and other documentations available on the web.

We get the following msg when trying to MQ Ping from Sender channel in
z/OS to receiver channel on Windows server:
CSQX620E ?QMEP CSQXPING System SSL error, 309
channel ????,
function 'gsk_secure_soc_init' RC=-36

Does anyone know what RC=-36 means?
Back to top
View user's profile Send private message
exerk
PostPosted: Thu Jun 05, 2008 10:59 pm    Post subject: Reply with quote

Jedi Council

Joined: 02 Nov 2006
Posts: 6339

These may seem obvious questions...but:

    1. Are the cipherspecs the same at both ends?
    2. Peer names correct?
    3. Windows end using V3 certificate and supported algorithm?

The last assumes RACF being used on the z/OS end.
_________________
It's puzzling, I don't think I've ever seen anything quite like this before...and it's hard to soar like an eagle when you're surrounded by turkeys.
Back to top
View user's profile Send private message
plebel
PostPosted: Mon Jun 09, 2008 3:44 am    Post subject: Reply with quote

Newbie

Joined: 05 Jun 2008
Posts: 2

1. The cipherspecs at both ends are the same: TRIPLE_DES_SHA_US

2. I left the Peer names blank on the sender and receiver channel. Could that be my problem? I tought that when the SSLPEER was left blank then no checking was done against the partner's Distinguished Name???

3. We are using Microsoft Window Server 2003 with IBM WebSphere MQ 5.3 and both support SSL V3.

We are using ACF2 on the mainframe.

Thanks for your help.
Back to top
View user's profile Send private message
exerk
PostPosted: Mon Jun 09, 2008 4:19 am    Post subject: Reply with quote

Jedi Council

Joined: 02 Nov 2006
Posts: 6339

Sorry I couldn't help further. I've recently experienced an issue with Win-to-z/OS where the Win end was using makecert.exe (I think) and the algorithm used for the cert is not supported by RACF, just wasn't sure whether you were hitting the same brick wall.

Did ACF2 report any error messages when adding the cert(s) to the keyring?
_________________
It's puzzling, I don't think I've ever seen anything quite like this before...and it's hard to soar like an eagle when you're surrounded by turkeys.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » General Discussion » CSQX620E & RC=-36 SSL problem
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.