ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » WebSphere Message Broker (ACE) Support » HTTPRequest Node SSL Connection

Post new topic  Reply to topic
 HTTPRequest Node SSL Connection « View previous topic :: View next topic » 
Author Message
SKK
PostPosted: Sat Oct 06, 2012 11:15 pm    Post subject: HTTPRequest Node SSL Connection Reply with quote

Acolyte

Joined: 09 May 2005
Posts: 67

Hi,

We are using HTTP Request node for HTTP request over SSL.

We havent generated any CSR from our side. We directly got PFX from our partner, which one listed shows 1 entries with 3 chain certficiate. This chain is for Personal Certificate, Intermediate and Trusted root.

We converted this pfx in to jks and used this as keystore in WMB, when we tested, we got getting "java.net.SocketException: Unconnected sockets not implemented" in our WMB exception list.

A Web Service request has detected a SOCKET error whilst invoking a web service located at host &1, on port &2, on path &3. - 1:[[4.0.18.15]]; 2:[[443]]; 3:[[/Autenticator/Service.asmx]]

An error occurred whilst performing an SSL socket operation - 1:[[createSocket]]; 2:[[java.net.SocketException: Unconnected sockets not implemented]]

second option, we extracted certificate by alias from jks and add in cacerts and created a new jks, this worked in WMB, but at partner side its failing and we are getting error response

Then we extracted individually personal,intermediate and Root certificates from pfx certificate.

In this tried two option,
1. We created jks out of pfx, this has 3 chain entries and added intermediate/root explcitly to JKS. but when tested, we got again " unconnected socket not implemented exception"

2. when then created a new jks- add only personal certificate to it and then added intermediate and trusted to cacerts, and we then got error reply from partner - "certificate error basically"

WMB 6.1.0.8 on AIX Server.

Can you please help us in this.
_________________
Regards,
SKK
Back to top
View user's profile Send private message
mqjeff
PostPosted: Sun Oct 07, 2012 4:25 am    Post subject: Reply with quote

Grand Master

Joined: 25 Jun 2008
Posts: 17447

http://publib.boulder.ibm.com/infocenter/wmbhelp/v8r0m0/topic/com.ibm.etools.mft.doc/ap12235_.htm
Back to top
View user's profile Send private message
SKK
PostPosted: Mon Oct 08, 2012 5:44 am    Post subject: Reply with quote

Acolyte

Joined: 09 May 2005
Posts: 67

Thanks Jeff

Artcile is for WMB v8, We are using WMB v6.1

Anycase, we have created keystore (added personal certificate) and added intermediate/root in cacerts.

we have changed broker properties and mqsisetdbparms

bounced broker as well. still no luck
_________________
Regards,
SKK
Back to top
View user's profile Send private message
fjb_saper
PostPosted: Mon Oct 08, 2012 11:12 am    Post subject: Reply with quote

Grand High Poobah

Joined: 18 Nov 2003
Posts: 20756
Location: LI,NY

SKK wrote:
Thanks Jeff

Artcile is for WMB v8, We are using WMB v6.1

Anycase, we have created keystore (added personal certificate) and added intermediate/root in cacerts.

we have changed broker properties and mqsisetdbparms

bounced broker as well. still no luck

Have you verified by any other means, (java etc...) that the certs will work at all? May be you have a bad combination?

Have fun
_________________
MQ & Broker admin
Back to top
View user's profile Send private message Send e-mail
mqjeff
PostPosted: Mon Oct 08, 2012 11:18 am    Post subject: Reply with quote

Grand Master

Joined: 25 Jun 2008
Posts: 17447

You might need to bounce the broker twice for certs to be picked up.

Particularly at 6.1...

There should be relatively the same information in the v6.1 info center, with a bit of hunting around.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » WebSphere Message Broker (ACE) Support » HTTPRequest Node SSL Connection
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.