ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » IBM MQ Security » OCSPAuthentication=optional ...or what?

Post new topic  Reply to topic
 OCSPAuthentication=optional ...or what? « View previous topic :: View next topic » 
Author Message
Robert_JR
PostPosted: Wed Jul 23, 2014 8:33 am    Post subject: OCSPAuthentication=optional ...or what? Reply with quote

Newbie

Joined: 02 May 2013
Posts: 2

Hello there,

I'm using
SSL:
OCSPAuthentication=optional

in my qm.ini files, as I was experiencing a lot of SSL errors (the certificate issuer servers were not reachable). But this 'optional' tells me: 'try to check it, but ignore it if you cannot check'.

Now my qmgrs are being moved to a new environment, where -unfortunatelly- the CA servers are reachable directly from the MQ servers.
I want to be 100% sure that the qmgrs will not check for cert revocation (will not check anything on the CA servers).

Is there any option here which can disable this? e.g.
OCSPAuthentication=no
OCSPAuthentication=disabled
or similar? I found 'optional' and 'warn', probably there are other options here.

Or does this guarantee that the qmgr will not check anything on the CA servers?
SSL:
OCSPCheckExtensions=No
OCSPAuthentication=optional

Thanks in advance.
Back to top
View user's profile Send private message
exerk
PostPosted: Wed Jul 23, 2014 11:22 am    Post subject: Reply with quote

Jedi Council

Joined: 02 Nov 2006
Posts: 6339

It's pretty explicit in the KB, that for OCSPCheckExtensions:

Quote:
NO: SSL and TLS channels do not try to check OCSP servers.

_________________
It's puzzling, I don't think I've ever seen anything quite like this before...and it's hard to soar like an eagle when you're surrounded by turkeys.
Back to top
View user's profile Send private message
tczielke
PostPosted: Wed Jul 23, 2014 11:48 am    Post subject: Reply with quote

Guardian

Joined: 08 Jul 2010
Posts: 941
Location: Illinois, USA

Also, in the "SSL and TLS stanza of the queue manager configuration file" -> http://www-01.ibm.com/support/knowledgecenter/SSFKSJ_8.0.0/com.ibm.mq.con.doc/q019040_.htm?lang=en

I would take note of this warning for these ini attributes, in case you were not aware:

Quote:
In each of the following cases, if the value supplied is not one of the valid values listed, then the default value is taken. No error messages are written mentioning that an invalid value is specified.


I am not sure if the OCSPAuthentication or OCSPCheckExtensions values are case sensitive or not, but the values are listed as upper case in the manual.
Back to top
View user's profile Send private message
Robert_JR
PostPosted: Wed Jul 23, 2014 8:52 pm    Post subject: Reply with quote

Newbie

Joined: 02 May 2013
Posts: 2

I'll build a test environment with these lines in the qm.ini files.
SSL:
CDPCheckExtensions=NO
OCSPAuthentication=OPTIONAL
OCSPCheckExtensions=NO

Then I'll tell the security guys to revoke my test cert.

Thanks guys for the tip.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » IBM MQ Security » OCSPAuthentication=optional ...or what?
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.