ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » WebSphere Interchange Server + Adapters » Establishing SSL Connection in MQ V6.0

Post new topic  Reply to topic
 Establishing SSL Connection in MQ V6.0 « View previous topic :: View next topic » 
Author Message
anantha sreenivasan
PostPosted: Tue Mar 27, 2007 5:21 am    Post subject: Establishing SSL Connection in MQ V6.0 Reply with quote

Acolyte

Joined: 26 Sep 2006
Posts: 72

Can somebody guide in establishing a SSL Connection between queue managers using Authentication Certificates?
Back to top
View user's profile Send private message
Vitor
PostPosted: Tue Mar 27, 2007 5:27 am    Post subject: Reply with quote

Grand High Poobah

Joined: 11 Nov 2005
Posts: 26093
Location: Texas, USA

Which parts of the procedure described in the Security manual do you need clarification on?
_________________
Honesty is the best policy.
Insanity is the best defence.
Back to top
View user's profile Send private message
wschutz
PostPosted: Tue Mar 27, 2007 10:52 am    Post subject: Reply with quote

Jedi Knight

Joined: 02 Jun 2005
Posts: 3316
Location: IBM (retired)

and there's a few excellent supportpacs for SSL, including:
MO04: WebSphere MQ SSL Wizard[/b]
_________________
-wayne
Back to top
View user's profile Send private message Send e-mail AIM Address
anantha sreenivasan
PostPosted: Tue Mar 27, 2007 10:59 am    Post subject: Reply with quote

Acolyte

Joined: 26 Sep 2006
Posts: 72

Actually, I did a SSL Connectivity using MQ V5.3 Queue Managers, where my queue managers use certificate obtained from globalsign.com and transact the encrypted data.

I update the keystore using amqmcert command. But this command is not supported in MQ V6.0.

So how to proceed by doing SSL Connectivity between MQ V6.0 Queue Managers?
Back to top
View user's profile Send private message
wschutz
PostPosted: Tue Mar 27, 2007 11:08 am    Post subject: Reply with quote

Jedi Knight

Joined: 02 Jun 2005
Posts: 3316
Location: IBM (retired)

Have you seen this:
http://publib.boulder.ibm.com/infocenter/wmqv6/v6r0/index.jsp?topic=/com.ibm.mq.csqzas.doc/c00stsu0.htm
_________________
-wayne
Back to top
View user's profile Send private message Send e-mail AIM Address
Vitor
PostPosted: Tue Mar 27, 2007 11:54 pm    Post subject: Reply with quote

Grand High Poobah

Joined: 11 Nov 2005
Posts: 26093
Location: Texas, USA

wschutz wrote:
Have you seen this:
http://publib.boulder.ibm.com/infocenter/wmqv6/v6r0/index.jsp?topic=/com.ibm.mq.csqzas.doc/c00stsu0.htm


Perhaps I should have been clearer; when I said "Security manual", I should really have said "Security manual or it's online version".
_________________
Honesty is the best policy.
Insanity is the best defence.
Back to top
View user's profile Send private message
gyadavil
PostPosted: Thu May 17, 2007 12:55 pm    Post subject: Re: Establishing SSL Connection in MQ V6.0 Reply with quote

Acolyte

Joined: 01 Feb 2005
Posts: 62

[quote="anantha sreenivasan"]Can somebody guide in establishing a SSL Connection between queue managers using Authentication Certificates?[/quote]

Not sure whether you want to do the same as I am going to explain or not. I did setup SSL for a SVR CONN Channel and it is pretty stright forward.

I would suggest to use GUI tool to generate the certificate and repository even from UNIX box.

1. Start the GUI
2. Create a CMS KeyRepository eg: SampleKeyRep.kdb
3. Add the Personal Certificate by just giving required information. I didin't try to play around with optional values.
4. I read somewhere the certificate lable must be ibmwebspheremq<qmgrname> all in lower case. Don't ask me what you need to use if you want to generate two certificates on the same queue manager. You got to try that for yourself.
4. Extract the SelfSigned Certificate eg; cert_ibmwebspheremq<qmgr>.arm
5. Set the QM Key Repository attribute to have this new key repository. Don't use the extention .kdb here
6. For one way communication, set SSLAUTH value on your channel to OPTIONAL and SSLCIPH value to a encryption algorithm. Make sure you pickup the algorithm based on your FIPS setting on QM.
7. Provide the extracted certificate to your client and also the CIPH value you used. I asked my client to use the same lable when they extracted the certificate.

For two way authentication, you need to set the SSLAUTH to REQUIRED and install client certificate in your Key Repository.


This worked for me for a JAVA client to connect to my QM and use this SSL feature.
Back to top
View user's profile Send private message
marcin.kasinski
PostPosted: Thu May 17, 2007 1:09 pm    Post subject: Re: Establishing SSL Connection in MQ V6.0 Reply with quote

Sentinel

Joined: 21 Dec 2004
Posts: 850
Location: Poland / Warsaw

You can also read this:

http://publib.boulder.ibm.com/infocenter/ieduasst/v1r1m0/topic/com.ibm.iea.wmq_v6/wmq/6.0/Security/MQ_SSL_channels_on_Windows.pdf?dmuid=20061231131305903569
_________________
Marcin
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » WebSphere Interchange Server + Adapters » Establishing SSL Connection in MQ V6.0
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.