ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » General IBM MQ Support » problem enabling SSL on SVRCONN channel

Post new topic  Reply to topic
 problem enabling SSL on SVRCONN channel « View previous topic :: View next topic » 
Author Message
ivanachukapawn
PostPosted: Sat Mar 18, 2006 1:21 pm    Post subject: problem enabling SSL on SVRCONN channel Reply with quote

Knight

Joined: 27 Oct 2003
Posts: 561

I very carefully followed the instructions (provided by the wizard, i.e. wmqsslwizard.jar in MO04) and configured a SVRCONN for SSL. The basic architecture of this endeavor is as follows:

Java Client on Windows XP
Queue Manager on Solaris
MQ6.0 with refresh pack 6.0.1.0 in both environments.

I told the wizard that I did not want client certification checking.

I ended up creating a Java Key Store on my Java Client, and a Keystore on the Queue Manager (type cms with kds suffix).

I created a certificate on the Solaris side, extracted it, and added it to the Java Key Store (client side), refreshed the security, and tested.

My Java Client gets a 2397.

When this failed, I got suspicious about my server side Queue Manager name which is QM.ATRADE_AP24_B

I mean, the underscores look like they might be a problem, because the certificate labelling convention ("ibmwebspheremq" + queuemanager name in lower case) is somehow used in matching certificates - also, this PEERNAME and DN mess is quite confusing. I don't know how its supposed to work.

Because of the suspicion referred to above, I created a test Queue Manager with a single character name (B), and when through the whole SSL configuration exercise again. When that was completed, I targeted my Java Client to the B Queue Manager and it got a connection on the SSL Encrypted SVRCONN channel.

This seems to corroborate my suspicion about the Queue Manager name with the underscores.

Anybody have any ideas as to how I can successfully configure SSL enabled SVRCONN channels on Queue Manager QM.AFAPT_AP24_B ?
Back to top
View user's profile Send private message
jefflowrey
PostPosted: Sat Mar 18, 2006 1:57 pm    Post subject: Reply with quote

Grand Poobah

Joined: 16 Oct 2002
Posts: 19981

Try looking at the mangled name for the queue manager (should be the name of the folder in /var/mqm/qmgrs/) to see how the cert should be named.

That is, try naming the cert with the mangled name of the queue manager, rather than the straight name.

I am not guaranteeing that _'s will get transformed in normal name mangling. I haven't double-checked the documentation.
_________________
I am *not* the model of the modern major general.
Back to top
View user's profile Send private message
wschutz
PostPosted: Sat Mar 18, 2006 2:00 pm    Post subject: Reply with quote

Jedi Knight

Joined: 02 Jun 2005
Posts: 3316
Location: IBM (retired)

hummmm....
Quote:
dspmqfls -m A_B.c -t qmgr A_B.c
WebSphere MQ Display MQ Files

QMGR Queue Manager Object
/var/mqm/qmgrs/A_B!c/qmanager/QMANAGER

[wschutz@wschutz Userdoc]$


_________________
-wayne
Back to top
View user's profile Send private message Send e-mail AIM Address
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » General IBM MQ Support » problem enabling SSL on SVRCONN channel
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.