|
RSS Feed - WebSphere MQ Support
|
RSS Feed - Message Broker Support
|
 |
|
Personal cert import Linux -> Win 7 corrupt |
« View previous topic :: View next topic » |
Author |
Message
|
askeggs |
Posted: Mon Apr 28, 2014 12:20 am Post subject: Personal cert import Linux -> Win 7 corrupt |
|
|
Novice
Joined: 30 Dec 2004 Posts: 14
|
Howdy,
Never had cause to setup SSL under MQ before apart from training x years ago. Now need to get it going. What a pain it is.
Current task is extracting a personal certificate from the Linux SSL repos and importing into the Window 7 repos. Hours later the best I have got is:
C:\ssl>runmqckm -cert -import -file x.pkcs12 -pw key -type pkcs12 -label ibmwebspheremqfunmq -target key.kdb -target_type cms -target_pw key
5724-H72 (C) Copyright IBM Corp. 1994, 2009. ALL RIGHTS RESERVED.
The password is invalid or the PKCS12 has been corrupted
or been created with an unsupported version of PKCS12.
Which is not really 100%. The password is correct.
The correponding export was:
runmqckm -cert -extract -db key.kdb -pw key -target x.pkcs12 -label ibmwebspheremqfunmq -format binary
-format binary or ascii give the same result.
The ascii format keyfile looks fine to me:
-----BEGIN CERTIFICATE-----
MIIBKzCB1qADAgECAghZVV9Xw0ZtcjANBgkqhkiG9w0BAQQFADAbMQswCQYDVQQLEwJ1czEMMAoG
...
hvcNAQEEBQADQQA61lJBWig2C7VLWeyefyPydom5VT9rAq/3BgS/bgxqwtTuFea5NTUkbEnC5fDA
czzlVbB4jTfB/b8CT4130aVT
-----END CERTIFICATE-----
Versions or runmqckm are not so far apart so currently doubt they would be the cause or corruption.
Linux:
=====
-bash-4.1$ runmqckm -version
IBM Key Management
Version : 7.0.3.28
Copyright IBM Corp. 1997 - 2006
All Rights Reserved
KJNI
============
@(#)CompanyName: IBM Corporation
@(#)LegalTrademarks: IBM
@(#)FileDescription: IBM Global Security Toolkit
@(#)FileVersion: 7.0.4.38
@(#)InternalName: gskkjni
@(#)LegalCopyright: Licensed Materials - Property of IBM GSKit
(C) Copyright IBM Corp.1995, 2007
All Rights Reserved. US Government Users
Restricted Rights - Use, duplication or disclosure
restricted by GSA ADP Schedule Contract with IBM Corp.
@(#)OriginalFilename: libgsk7kjni.so
@(#)ProductName: gsk7d (GoldCoast Build) 111031
@(#)ProductVersion: 7.0.4.38
@(#)ProductInfo: 11/10/24.03:30:45.11/10/31.11:22:04
@(#)CMVCInfo: gsk7d_111024/gsk7d_doc gsk7d_111024/gsk7d_ssl gsk7d_110519/gsk7d_pkg gsk7d_111024/gsk7d_ikm gsk7d_090120/gsk7d_acme gsk7d_111024/gsk7d_cms gsk7d_111024/gsk7d_support
Win 7:
====
C:\ssl>runmqckm -version
5724-H72 (C) Copyright IBM Corp. 1994, 2009. ALL RIGHTS RESERVED.
IBM Key Management
Version : 7.0.4.27
Copyright IBM Corp. 1997 - 2006
All Rights Reserved
KJNI
============
@(#)CompanyName: IBM Corporation
@(#)LegalTrademarks: IBM
@(#)FileDescription: IBM Global Security Toolkit
@(#)FileVersion: 7.0.4.27
@(#)InternalName: gskkjni
@(#)LegalCopyright: Licensed Materials - Property of IBM GSKit
(C) Copyright IBM Corp.1995, 2007
All Rights Reserved. US Government Users
Restricted Rights - Use, duplication or disclosure
restricted by GSA ADP Schedule Contract with IBM Corp.
@(#)OriginalFilename: gsk7kjni.dll
@(#)ProductName: gsk7d (GoldCoast Build) 091112
@(#)ProductVersion: 7.0.4.27
@(#)ProductInfo: 09/11/04.21:13:30.09/11/12.12:34:01
@(#)CMVCInfo: gsk7d_090814/gsk7d_doc gsk7d_091112/gsk7d_ssl gsk7d_090907
/gsk7d_pkg gsk7d_091105/gsk7d_ikm gsk7d_090120/gsk7d_acme gsk7d_091111/gsk7d_cms
gsk7d_090120/gsk7d_support
Am I missing something obvious? _________________ Adam. |
|
Back to top |
|
 |
fjb_saper |
Posted: Mon Apr 28, 2014 7:51 am Post subject: |
|
|
 Grand High Poobah
Joined: 18 Nov 2003 Posts: 20756 Location: LI,NY
|
Code: |
runmqckm -cert -import -file x.pkcs12 -pw key -type pkcs12 -label ibmwebspheremqfunmq -target key.kdb -target_type cms -target_pw key |
works in concert with
Code: |
runmqckm -cert -export |
But you are using
Code: |
runmqckm -cert -extract |
which will only extract the public key X509.
As such you should be using
Code: |
runmqckm -cert -add |
to add the cert to your truststore.
Have fun  _________________ MQ & Broker admin |
|
Back to top |
|
 |
askeggs |
Posted: Tue Apr 29, 2014 3:52 pm Post subject: |
|
|
Novice
Joined: 30 Dec 2004 Posts: 14
|
That did it.
Thank you. _________________ Adam. |
|
Back to top |
|
 |
|
|
 |
|
Page 1 of 1 |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|
|
|