|
RSS Feed - WebSphere MQ Support
|
RSS Feed - Message Broker Support
|
 |
|
Key database certificate mis-labelled |
« View previous topic :: View next topic » |
Author |
Message
|
bpitawan |
Posted: Wed Sep 01, 2010 1:24 pm Post subject: Key database certificate mis-labelled |
|
|
Newbie
Joined: 01 Sep 2010 Posts: 2 Location: Toronto, Canada
|
Lads (and ladies),
So, I've followed the documentation for creating a key database, certificate request, getting it signed, importing the CA cert, etc., etc. Everything was going swimmingly, until I checked my work and noticed I had labelled it thus:
ibmwebsphwere<qmgr name>
I don't think I'm completely hosed, as this queue manager is only connecting to one other queue manager. In theory, if this is the default certificate in that key store, Websphere MQ will pick that up if it can't find the correctly labelled cert, aye?
The correct way to fix it would be to re-create the cert request, have it signed again and so on and so forth. Is there any way to cheat? Can a cert in a key store be re-labelled?
Thanks for your time and attention. I checked around and did some searching, but nothing came up that matched my little dilemma.
Regards,
Ben |
|
Back to top |
|
 |
fjb_saper |
Posted: Wed Sep 01, 2010 2:27 pm Post subject: |
|
|
 Grand High Poobah
Joined: 18 Nov 2003 Posts: 20756 Location: LI,NY
|
If you can do with an internal CA it is faster to recreate a cert chain.
If you are dealing with a public CA you may have to ask for another cert.
Have fun  _________________ MQ & Broker admin |
|
Back to top |
|
 |
mqjeff |
Posted: Wed Sep 01, 2010 2:57 pm Post subject: |
|
|
Grand Master
Joined: 25 Jun 2008 Posts: 17447
|
The label is not a part of the certificate.
You should be able to export the cert into a different format - like PKS12 or something - that doesn't support the label. Then you can reimport things into a "proper MQ" keystore that does support the label. |
|
Back to top |
|
 |
bpitawan |
Posted: Fri Sep 03, 2010 10:18 am Post subject: |
|
|
Newbie
Joined: 01 Sep 2010 Posts: 2 Location: Toronto, Canada
|
mqjeff wrote: |
The label is not a part of the certificate.
You should be able to export the cert into a different format - like PKS12 or something - that doesn't support the label. Then you can reimport things into a "proper MQ" keystore that does support the label. |
Great idea.
Thanks, mqjeff, this worked like a charm. |
|
Back to top |
|
 |
|
|
 |
|
Page 1 of 1 |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|
|
|