ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » IBM MQ Security » SSL channels sdr/rcvr : exchange of public key ?

Post new topic  Reply to topic
 SSL channels sdr/rcvr : exchange of public key ? « View previous topic :: View next topic » 
Author Message
bcostacurta
PostPosted: Thu May 27, 2010 10:57 am    Post subject: SSL channels sdr/rcvr : exchange of public key ? Reply with quote

Acolyte

Joined: 10 Dec 2009
Posts: 71
Location: Luxembourg

Dears,

I currently setup channels sender / receiver between two MQSeries servers (different sites and different compagnies) to exchange message with SSL encryption.
Each MQSeries has its own CA root authorities certificate and private certificate (issued by this CA) into its keyring.

What about the public keys ?
Do we need to exchange public key (not private of course) and related CA root ?

So each keyring should contain :

- own CA root
- own private certificate (with key pair private/public) signed by the CA root.
- the other part CA root
- the other part public key

Is this correct ?
If so, do we need to exchange these files manually, or does the channel protocol negotiate the public key of other part automatically (ie. if at least CA root is present on the keyring) ?

Thanks for attention.
Bye,
Bruno
Back to top
View user's profile Send private message
exerk
PostPosted: Thu May 27, 2010 1:04 pm    Post subject: Reply with quote

Jedi Council

Joined: 02 Nov 2006
Posts: 6339

The minimum requirements for each key store are:

1. A personal certificate;
2. A copy of the CA certificate that signed the above personal certificate; and
3. A copy of the CA certificate used to sign the other parties personal certificate.
_________________
It's puzzling, I don't think I've ever seen anything quite like this before...and it's hard to soar like an eagle when you're surrounded by turkeys.
Back to top
View user's profile Send private message
bcostacurta
PostPosted: Fri May 28, 2010 3:54 am    Post subject: Reply with quote

Acolyte

Joined: 10 Dec 2009
Posts: 71
Location: Luxembourg

Thanks for confirmation.

If a MQSeries called A sends encrypted message to B it needs to encrypt the message with public key of B. Correct ?

So how will A obtain public key of B ?
Could it be negotiated via the two MQSeries when connection is established via a request / response between both MQSeries ?

Thanks for attention.

Bye,
Bruno
Back to top
View user's profile Send private message
exerk
PostPosted: Fri May 28, 2010 4:10 am    Post subject: Reply with quote

Jedi Council

Joined: 02 Nov 2006
Posts: 6339

Two SupportPacs: MH03 and MO04
_________________
It's puzzling, I don't think I've ever seen anything quite like this before...and it's hard to soar like an eagle when you're surrounded by turkeys.
Back to top
View user's profile Send private message
bcostacurta
PostPosted: Tue Jun 08, 2010 12:37 am    Post subject: Reply with quote

Acolyte

Joined: 10 Dec 2009
Posts: 71
Location: Luxembourg

It works as following requirements are fulfill :

...
The minimum requirements for each key store are:

1. A personal certificate
2. A copy of the CA certificate that signed the above personal certificate; and
3. A copy of the CA certificate used to sign the other parties personal certificate.
...

So *I suppose from here* that MQSeries protocols exchange public key between each MQSeries servers to be able to encrypt message on sender side to be decrypted on receiver side.

Bye,
Bruno
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » IBM MQ Security » SSL channels sdr/rcvr : exchange of public key ?
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.