Posted: Mon Dec 01, 2008 3:14 am Post subject: Questions on SSL Certificate Management
Acolyte
Joined: 24 Jul 2001 Posts: 60
Dear All,
I have some questions on the way MQ GSK facility & the qmgr manage and use the qmgr certificates.
a) When we first generate a cert request (CSR) using the gsk7cmd we specify the label and also the Key Database where the certs are stored.
The gsk7cmd is expected to generate a key pair : private key and a public key.
Is the private key then stored on the Key Database directly at that point ?
and the public key becomes part of the CSR ?
Also is the CSR digitally signed using the private key ?
b) Later when the CA signs and returns the certificate it is added using the "receive" option of the gsk7cmd. I see we don't mention the label here. This is different from the way we add the CA certs with the "add" option. Any reason for this difference ? Is it because label is part of the qmgr cert ?
c) Are both keys located in the key database by the qmgr using the label ?
I can't find answers to these in the IBM docs too.
Answers would be greatly helpful.
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum