|  | 
 
  
    | RSS Feed - WebSphere MQ Support | RSS Feed - Message Broker Support |  
 
  
	|    |  |  
  
	| SSLFIPS questions for MQ Server 7.5.0.3 | « View previous topic :: View next topic » |  
  	| 
		
		
		  | Author | Message |  
		  | LouML | 
			  
				|  Posted: Thu Apr 24, 2014 10:00 am    Post subject: SSLFIPS questions for MQ Server 7.5.0.3 |   |  |  
		  |  Partisan
 
 
 Joined: 10 Nov 2005Posts: 305
 Location: Jersey City, NJ / Bethpage, NY
 
 | 
			  
				| We generally use TLS_RSA_WITH_AES_128_CBC_SHAf with our external channels. However, one company requires FIPS_WITH_3DES_EDE_CBC_SHA. When we try this we get the following error: 
 
 
   
	| Code: |  
	| AMQ9719: Invalid CipherSpec for FIPS mode. 
 EXPLANATION:
 The user is attempting to start a channel on a queue manager or MQ client which
 has been configured to run in FIPS mode. The user has specified a CipherSpec
 which is not FIPS-compliant. The channel is 'P.AAAAA_BBBBB.C'; in some cases
 its name cannot be determined and so is shown as '????'.
 ACTION:
 Redefine the channel to run with a FIPS-compliant CipherSpec. Alternatively,
 the channel may be defined with the correct CipherSpec and the queue manager or
 MQ client should not be running in FIPS mode; if this is the case, ensure that
 FIPS mode is not configured. Once the error is corrected, restart the channel.
 |  
 One of the possible reasons is that the cipher spec is not FIPS compliant. Sinnce FIPS_WITH_3DES_EDE_CBC_SHA has FIPS in it I assumed it was FIPS compliant. Can anyone confirm if this is the case?
 
 The other possibility is that we currently have SSLFIPS(YES) on the queue manager. I will need to change this to SSLFIPS(NO).
 
 Do I need to recycle the queue manager or just REFRESH SECURITY TYPE(SSL) after making the change?
 
 Also, I know the refresh command causes the running channels to stop. Is that ALL running channels, or just channels using SSL?
 _________________
 Yeah, well, you know, that's just, like, your opinion, man. - The Dude
 |  |  
		  | Back to top |  |  
		  |  |  
		  | fjb_saper | 
			  
				|  Posted: Thu Apr 24, 2014 10:53 am    Post subject: |   |  |  
		  |  Grand High Poobah
 
 
 Joined: 18 Nov 2003Posts: 20767
 Location: LI,NY
 
 |  |  
		  | Back to top |  |  
		  |  |  
		  |  |  |  
  
	|    |  | Page 1 of 1 |  
 
 
  
  	| 
		
		  | 
 
 | You cannot post new topics in this forum You cannot reply to topics in this forum
 You cannot edit your posts in this forum
 You cannot delete your posts in this forum
 You cannot vote in polls in this forum
 
 |  |  |  |