Posted: Sun May 21, 2017 7:19 pm Post subject: SSL Channel starting with blank SSLCIPH on one end
Voyager
Joined: 26 Jul 2014 Posts: 77
Hello All,
I faced an issue where I witnessed the SSL Channels started with SSLCIPH blank on one end of the MQ setup.
I was migrating existing MQ Clustered non SSL Setup to a SSL Setup.
I had changed the CLUSRCVR Channel definition to include the SSLCIPH attribute TLS_RSA_WITH_AES_256_CBC_SHA and SSLCIPH as REQUIRED(to allow Mutual Auth)
Now the CLUSSDR end of the channel is starting just fine and comes to running start with SSLPEER value populated with the cert details even when I did not provide the SSLCIPH values at the CLUSSDR channel end.
I am wondering how is it working provided that the SSLCIPH value must be same on both ends of the channels
Joined: 09 May 2013 Posts: 1959 Location: Bay of Plenty, New Zealand
A manual CLUSSDR channel definition is only used as a bootstrap to get the cluster going. After things are up and running, the manual CLUSSDR channel is merged in the Repository details with the template CLUSRCVR channel definition from the queue manager at the other end. This will mean that the CLUSSDRB (Cluster-sender both auto+manual) will have the SSL fields from the CLUSRCVR, hence how it worked.
To see the actual channel definition that will be used, don't use DISPLAY CHANNEL on the CLUSSDR, but instead use DISPLAY CLUSQMGR.
Cheers
Morag _________________ Morag Hughson @MoragHughson
IBM MQ Technical Education Specialist
Get your IBM MQ training here! MQGem Software
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum