ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » IBM MQ Java / JMS » 2397 error testing SSL with JAVA on XP client and Unix QM

Post new topic  Reply to topic
 2397 error testing SSL with JAVA on XP client and Unix QM « View previous topic :: View next topic » 
Author Message
MQTrigger
PostPosted: Tue Feb 03, 2004 12:41 am    Post subject: 2397 error testing SSL with JAVA on XP client and Unix QM Reply with quote

Apprentice

Joined: 01 Dec 2002
Posts: 39

Hi

I get the 2397 error and when trying to connect to the QM using some java code I have. It's telling me that the certificate is unknown. I am only looking to get a 1 way authentication working first, then worry about the 2 way. amqsput/get tests work but the java test is not working. I imported the CA certificate from the queue manager into the default cacert truststore on the client (XP box). I also tried importing the personal certificate but still no luck. I am using keytool to import the certificate into the truststore. Can someone tell me if they have set this up successfully and what I may potentially be doing wrong when importing my certificate?

thanks in advance.
Back to top
View user's profile Send private message
vennela
PostPosted: Tue Feb 03, 2004 7:29 am    Post subject: Reply with quote

Jedi Knight

Joined: 11 Aug 2002
Posts: 4055
Location: Hyderabad, India

I am not sure if this helps, but look at JasonE's answer and try that solution

http://www.mqseries.net/phpBB2/viewtopic.php?t=13124&highlight=ssl+java
Back to top
View user's profile Send private message Send e-mail Visit poster's website
MQTrigger
PostPosted: Tue Feb 03, 2004 8:16 am    Post subject: Code Reply with quote

Apprentice

Joined: 01 Dec 2002
Posts: 39

Hi

Yup, that's the code I'm also using. The code works from a Unix client so I know there are no problems with it. I believe it could be a problem with the certificate as indicated in the output on the screen. I import the certificate to the client from the server. On a Unix client, I import both the ibmwebspheremq<qm> and ibmwebspheremq<userid> certs into the cacert trust store and it works successfully. Now I'm trying to accomplish the same on a windows client but it doesn't seem to work... I'll keep trying. Could it be a label issue? If anyone has details ..thanks in advance.
Back to top
View user's profile Send private message
MQTrigger
PostPosted: Thu Feb 05, 2004 11:33 pm    Post subject: Solution Reply with quote

Apprentice

Joined: 01 Dec 2002
Posts: 39

I just wanted to let everyone know I had the wrong classpath and java_home that was pointing to the wrong truststore.

I managed to get it to work.

Although I still am trying to find out why the IBM security redbook speficies that certificates for MQ should have the label names of ibmwebspheremq<qm> and ibmwebspheremq<userid>. It does mention to use lowercase and use these names so that it's distinguishable between other app certificates. Is this the only reason? I performed a test with a different name and it worked so I'm not sure if there was some sort of requirement MQ looks for. thanks
Back to top
View user's profile Send private message
crossland
PostPosted: Mon Mar 15, 2004 8:00 am    Post subject: Reply with quote

Master

Joined: 26 Jun 2001
Posts: 248

Can I confirm that the ibmwebspheremq<userid> only applies to MQ clients and not to java clients running on Windows?

Thanks,

Tim Crossland
http://www.solent-consultancy.com
Back to top
View user's profile Send private message
JasonE
PostPosted: Mon Mar 15, 2004 8:12 am    Post subject: Reply with quote

Grand Master

Joined: 03 Nov 2003
Posts: 1220
Location: Hursley

The certificate label is irrelevant for clients running in Java or running on the windows platform. Only those using GSKit for certificates are impacted by the label name.

On windows there is the concept of assigning a certificate to be used. On unix the assiging is 'implied' by having a specific label.
Back to top
View user's profile Send private message
MQTrigger
PostPosted: Mon Mar 15, 2004 3:12 pm    Post subject: Windows Certs Reply with quote

Apprentice

Joined: 01 Dec 2002
Posts: 39

Windows uses a numberic handling of certificates.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » IBM MQ Java / JMS » 2397 error testing SSL with JAVA on XP client and Unix QM
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.