|
RSS Feed - WebSphere MQ Support
|
RSS Feed - Message Broker Support
|
 |
|
Error creating Self Signed Certificates on V7 |
« View previous topic :: View next topic » |
Author |
Message
|
smeunier |
Posted: Wed Jul 14, 2010 9:52 am Post subject: Error creating Self Signed Certificates on V7 |
|
|
 Partisan
Joined: 19 Aug 2002 Posts: 305 Location: Green Mountains of Vermont
|
Hi,
I have been trying to create a self signed certificate on a V7 installation using the following gsk7cmd command:
Code: |
gsk7cmd -cert -create -db key.kdb -pw abc2def -label ibmwebspheremqabcmq123 -dn "CN=tci.xxx.yyy.com,O=IBM,OU=XYZ Corporation,L=BTV,ST=VT,C=US"
|
and receive the following error:
Code: |
The function is not supported for cryptographic tokens.
|
I have been unable to find little meaning of this message. Has anyone seen this? |
|
Back to top |
|
 |
jeevan |
Posted: Wed Jul 14, 2010 10:40 am Post subject: Re: Error creating Self Signed Certificates on V7 |
|
|
Grand Master
Joined: 12 Nov 2005 Posts: 1432
|
smeunier wrote: |
Hi,
I have been trying to create a self signed certificate on a V7 installation using the following gsk7cmd command:
Code: |
gsk7cmd -cert -create -db key.kdb -pw abc2def -label ibmwebspheremqabcmq123 -dn "CN=tci.xxx.yyy.com,O=IBM,OU=XYZ Corporation,L=BTV,ST=VT,C=US"
|
and receive the following error:
Code: |
The function is not supported for cryptographic tokens.
|
I have been unable to find little meaning of this message. Has anyone seen this? |
At the end of the message there should an SSL error code returned. what is that?
also, it would be good not to make people guess who are supposed to help you about your env, os/mq version. |
|
Back to top |
|
 |
fjb_saper |
Posted: Wed Jul 14, 2010 4:20 pm Post subject: |
|
|
 Grand High Poobah
Joined: 18 Nov 2003 Posts: 20756 Location: LI,NY
|
Browse the security forum. There is comprehensive pdf referenced there on how to set this all up. Also if you are dealing only with internal stuff you might consider setting up an internal CA or certificate authority and treat the certs
as if they were from a public CA. (also described in said pdf)
Also I would not use O=IBM OU=xyz.corp.com
Use instead O=xyz corp OU=app name or organizational Unit in xyz corp.
Once you get that working you can try with multiple OU occurrences...
Have fun  _________________ MQ & Broker admin |
|
Back to top |
|
 |
|
|
 |
|
Page 1 of 1 |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|
|
|