ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » IBM MQ Installation/Configuration Support » self signed + 3rd party cert SSL on 1 qmgr

Post new topic  Reply to topic
 self signed + 3rd party cert SSL on 1 qmgr « View previous topic :: View next topic » 
Author Message
tgow
PostPosted: Mon Mar 21, 2005 9:16 am    Post subject: self signed + 3rd party cert SSL on 1 qmgr Reply with quote

Novice

Joined: 02 Dec 2004
Posts: 15
Location: Reston, VA

Hi.

I would like to make this work if at all possible on ONE (1) queue manager.


I have one qmgr, in this example named QM1. I have 3 clients, we'll call them clientA, clientB, and clientC

Here's my system details:
QM1 is websphere MQ 5.3 cd07 on a sunOS / solaris 2.8 server.

I have a 3rd party Entrust cert, ibmwebspheremqqm1 which works perfectly fine for ClientA and ClientB. Both are using SDR/RCVR.

ClientC would like us to send a key after we make a request from their private CA for a ClientC self-signed private signing key for use on our QM1. (They are a Bank, and innately don't trust 3rd party for some reason.)

ClientC will be using SVR/RCVR, where we will be the inactive party awaiting inbound connections for gets and puts from our server will be done actively via the RCVR channel. I have no defintions set up for ClientC's connection yet, as I want to make sure this might work before I give it a go.

Basically, what I'd like to do is install this second certificate as well as their Private CA for use with only ClientC. Is there a way I can install this signing cert into our keystore/repository, and have the client specify in the SSLPEER definition (or some other field) that they'd like to use this secondary cert for SSL connectivity instead of the default 3rd party cert? I was thinking instead of naming it with a default label of "ibmwebspheremqqm1", perhaps I could make it something else like "ibmwebspheremq.qm1".

Perhaps using SSLPEER(OU="something different than our default cert")?


Is this feasible? Thoughts are very appreciated!


Thanks,
-Seth
Back to top
View user's profile Send private message
malammik
PostPosted: Mon Mar 21, 2005 3:55 pm    Post subject: Re: self signed + 3rd party cert SSL on 1 qmgr Reply with quote

Partisan

Joined: 27 Jan 2005
Posts: 397
Location: Philadelphia, PA

tgow wrote:

ClientC would like us to send a key after we make a request from their private CA for a ClientC self-signed private signing key for use on our QM1. (They are a Bank, and innately don't trust 3rd party for some reason.)


Basically, what I'd like to do is install this second certificate as well as their Private CA


Ok. Something's got to be wrong here. Bank will not give out their private key otherwise it is not private anymore. What do you mean when you say Private CA?

Are you trying to have data signed or signed and encrypted?
_________________
Mikhail Malamud
http://www.netflexity.com
http://groups.google.com/group/qflex
Back to top
View user's profile Send private message Visit poster's website AIM Address
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » IBM MQ Installation/Configuration Support » self signed + 3rd party cert SSL on 1 qmgr
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.