|
RSS Feed - WebSphere MQ Support
|
RSS Feed - Message Broker Support
|
 |
|
SSL problem |
« View previous topic :: View next topic » |
Author |
Message
|
alphamale |
Posted: Mon Jul 14, 2008 4:42 am Post subject: SSL problem |
|
|
 Novice
Joined: 09 Feb 2005 Posts: 12 Location: UK
|
Hi
I have two queue managers using SSL to secure a SDR/RCVR channel pair (one QM on AIX, the other on HP-UX)
The SDR channel from QMA to QMB has SSLCIPH set, SSLPEER set, and SSLCAUTH to 'REQUIRED' at both ends. The channel starts successfully.
The SDR channel from QMB to QMA has only SSLCIPH set at both ends (same value) and the channel will not start - get AMQ9665 reported at QMB, and AMQ9633 reported at QMA.
The AMQ9633 implies there is something wrong with a certificate (the CRL option doesn't apply), but doesn't indicate whose certificate - I assume it may be QMA's as QMB is the client and it shouldn't be sending its certificate (SSLCAUTH is OPTIONAL).
However, on the QMA to QMB channel, SSLCAUTH was REQUIRED at both ends, so each QMgr will have authenticated with each other, implying that both certificates could be found/exchanged (they even validated each others Distinguised Name info).
So on the QMB to QMA channel, does anyone have any ideas which certificate it might have an issue with, and why this should be so when the other channel works ok ? |
|
Back to top |
|
 |
fjb_saper |
Posted: Mon Jul 14, 2008 4:23 pm Post subject: |
|
|
 Grand High Poobah
Joined: 18 Nov 2003 Posts: 20756 Location: LI,NY
|
Well at a guess.
QMA to QMB works QMB has QMA's certificate (public key)
QMB to QMA doesn't work. QMA doesn't have QMB's certificate (public key)
Does QMB even have a unique private key?
Enjoy  _________________ MQ & Broker admin |
|
Back to top |
|
 |
nageshshiv |
Posted: Tue Jul 15, 2008 2:11 am Post subject: |
|
|
Apprentice
Joined: 09 May 2008 Posts: 30
|
Could you pls provide the following things
SDR & RCVR Channel names on QMB
SDR & RCVR Channel names on QMA
Regards,
Nagesh |
|
Back to top |
|
 |
|
|
 |
|
Page 1 of 1 |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|
|
|