ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » IBM MQ Security » Request/Renew Qmgr Cert with changes

Post new topic  Reply to topic
 Request/Renew Qmgr Cert with changes « View previous topic :: View next topic » 
Author Message
neocruz
PostPosted: Tue Aug 16, 2011 10:27 am    Post subject: Request/Renew Qmgr Cert with changes Reply with quote

Acolyte

Joined: 13 Jun 2004
Posts: 54

I've performed searches and can't find an answer.

On my Windows system, I have a Qmgr personal Cert that will expire in 30 days. Our standards have changed and I must use a size of 2048 instead of the original requested size of 1024. Recreate request will ask for the incorrect size, of 1024, for the certificate.

When I try to generate an original request, using the size 2048, I get an errror that says the lable already exists in the database. This is True.

How do I get around this?

MQ V6.0.2.2
Windows 2003 R2

Thanks in Advance.
_________________
Rich
Back to top
View user's profile Send private message
mqjeff
PostPosted: Tue Aug 16, 2011 10:33 am    Post subject: Reply with quote

Grand Master

Joined: 25 Jun 2008
Posts: 17447

Create a new keystore. Generate the request there. Receive the certificate into that keystore.

Then either use the new keystore or export/import the new, larger, cert into the old keystore.
Back to top
View user's profile Send private message
neocruz
PostPosted: Tue Aug 16, 2011 10:44 am    Post subject: Reply with quote

Acolyte

Joined: 13 Jun 2004
Posts: 54

Thanks Jeff.

Not "my" first choice but....if I choose to import the larger cert into the old keystore,once received into the new keystore, how much of a pain is that?
1. I can import it without a request being there?
2. What will happen to the old personal cert? Delete it first then import?
3. I take it there are no changes to be made if I stay with the same cypher, etc?
4. Basically, what process would you recommend?

Again, thanks for your help.
_________________
Rich
Back to top
View user's profile Send private message
fjb_saper
PostPosted: Tue Aug 16, 2011 11:05 am    Post subject: Reply with quote

Grand High Poobah

Joined: 18 Nov 2003
Posts: 20696
Location: LI,NY

mqjeff wrote:
Create a new keystore. Generate the request there. Receive the certificate into that keystore.

Then either use the new keystore or export/import the new, larger, cert into the old keystore.

Is just importing the larger cert into the keystore enough? Don't you need to import as well the corresponding private key into the keystore?

I thought the signed cert contained only the public key?
_________________
MQ & Broker admin
Back to top
View user's profile Send private message Send e-mail
mqjeff
PostPosted: Tue Aug 16, 2011 11:12 am    Post subject: Reply with quote

Grand Master

Joined: 25 Jun 2008
Posts: 17447

fjb_saper wrote:
mqjeff wrote:
Create a new keystore. Generate the request there. Receive the certificate into that keystore.

Then either use the new keystore or export/import the new, larger, cert into the old keystore.

Is just importing the larger cert into the keystore enough? Don't you need to import as well the corresponding private key into the keystore?

I thought the signed cert contained only the public key?


There's a difference between "export/import" and "extract/recieve".
Back to top
View user's profile Send private message
fjb_saper
PostPosted: Tue Aug 16, 2011 11:45 am    Post subject: Reply with quote

Grand High Poobah

Joined: 18 Nov 2003
Posts: 20696
Location: LI,NY

I think I got confused for a minute there. Thanks for setting us all straight.
_________________
MQ & Broker admin
Back to top
View user's profile Send private message Send e-mail
exerk
PostPosted: Tue Aug 16, 2011 12:22 pm    Post subject: Reply with quote

Jedi Council

Joined: 02 Nov 2006
Posts: 6339

Life can be made easier by having an A and B key store. If A is the 'current' key store you generate a new certificate request in the B key store, receive the signed certificate, 'flip' the SSLKEYR attribute of the queue manager, and refresh security (SSL stylee). if it works, clear out the A key store ready for next year - if not, 'flip' it back to the A key store and sort the problem. Rinse and repeat...

Elegantly simple, and if you script it you can use a parameter file to feed in the values of key length, DN values etc., and cater for changes year on year.
_________________
It's puzzling, I don't think I've ever seen anything quite like this before...and it's hard to soar like an eagle when you're surrounded by turkeys.


Last edited by exerk on Wed Aug 17, 2011 2:43 pm; edited 1 time in total
Back to top
View user's profile Send private message
neocruz
PostPosted: Wed Aug 17, 2011 5:27 am    Post subject: Reply with quote

Acolyte

Joined: 13 Jun 2004
Posts: 54

Thanks to everyone for your help.
_________________
Rich
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » IBM MQ Security » Request/Renew Qmgr Cert with changes
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.