ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » IBM MQ Installation/Configuration Support » using openssl unix generated cert on a Windows qmgr

Post new topic  Reply to topic
 using openssl unix generated cert on a Windows qmgr « View previous topic :: View next topic » 
Author Message
slate
PostPosted: Fri Nov 19, 2004 8:02 am    Post subject: using openssl unix generated cert on a Windows qmgr Reply with quote

Newbie

Joined: 05 Aug 2004
Posts: 9

We are currently using SSL enabled channels on UNIX without issue(Solaris 2.8 and MQ 5.3 CSD07). Now we want to incorporate windows into the mix. When I generate the certificates on UNIX and transfer them up to Windows, they get loaded in the qmgr store fine, but I am unable to assign any certificates to the qmgr because none of these certs have a private key. Has anybody successully generated certs on UNIX and gotten them to work on windows( win2000, mq 5.3 csd08).

Any help would be greatly appreciated.

Regards,

Scott
Back to top
View user's profile Send private message
Anirud
PostPosted: Fri Nov 19, 2004 8:35 am    Post subject: Reply with quote

Master

Joined: 12 Feb 2004
Posts: 285
Location: Vermont

Are you trying to create a certificate on a UNIX system for a Windows queue manager and trying to assign it to the Windows queue manager?
Back to top
View user's profile Send private message Visit poster's website
slate
PostPosted: Fri Nov 19, 2004 10:00 am    Post subject: Reply with quote

Newbie

Joined: 05 Aug 2004
Posts: 9

Yes.

Openssl generated certificates are supposed to be platform independant.

The certs load into the store fine. They just cannot be assigned to the qmgr.

Thanks...
Back to top
View user's profile Send private message
jefflowrey
PostPosted: Fri Nov 19, 2004 10:22 am    Post subject: Reply with quote

Grand Poobah

Joined: 16 Oct 2002
Posts: 19981

It sounds to me like you are not exporting the private certificate/key as well as the public.

If you need to move an entire cert to another machine, you need to export both pieces.

I don't have instructions for doing this with openssl, but I'm sure they're easy to find.
_________________
I am *not* the model of the modern major general.
Back to top
View user's profile Send private message
slate
PostPosted: Mon Nov 22, 2004 8:14 am    Post subject: Reply with quote

Newbie

Joined: 05 Aug 2004
Posts: 9

Can you explain what you mean by both pieces? Here is my scenario. I have a QM on Solaris, QM1,and QM on Windows QM2. I created two set of certificates on the Solaris box, one for each queue manager. I then did the export for the windows QM2 certs. I used the following command:

gsk6cmd -cert -export -db <db> -pw <pw> -label ibmwebs..... -type pkcs12 -target <filename>

This appeared to work since I was able to load and assign the certs to the windows queue manager. I still get an authentication error when trying to start the channels. It says the public key cannot validate the certificate. One of the things we are doing on the unix side is converting the certs to x509 certs (PEM format) before we load them into the key repository. I'm not sure if this has any effect on windows, but I am not a digital certificat expert by any stretch of the means.

Any guidance would be greatly appreciated.

Thanks,

Scott
Back to top
View user's profile Send private message
slate
PostPosted: Mon Nov 22, 2004 12:27 pm    Post subject: - updated Reply with quote

Newbie

Joined: 05 Aug 2004
Posts: 9

OK. I got the certificate exported correctly, and loaded the root certificate in the windows key store first and now I have a valid certificate.

Now a new problem. I have the cipherspec set to TRIPLE_DES_SHA_US on all 4 channels (both pairs). The channel from Solaris to windows now works fine, but the channel from windows to solaris will only work with encryption turned off altogether. Has anyone else seen this behavior?

Thanks,

Scott
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » IBM MQ Installation/Configuration Support » using openssl unix generated cert on a Windows qmgr
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.