ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » IBM MQ Security » SSL Connection with MQ/Explorer

Post new topic  Reply to topic
 SSL Connection with MQ/Explorer « View previous topic :: View next topic » 
Author Message
pfarrel
PostPosted: Thu Dec 01, 2011 10:21 am    Post subject: SSL Connection with MQ/Explorer Reply with quote

Centurion

Joined: 16 Mar 2004
Posts: 120
Location: Kansas City

I have set up an SSL connection from an MQ client on windows to an MQ queue manager on AIX. I used the MO04 support pack, and I was able to complete all the tasks and get the sample program working.
Now I'm ready to move on and connect with MQ/Explorer using the same SSL SVRCONN channel. I am having problems making that work.
Currently I am getting this message at the queue manager end:
AMQ9639: Remote channel 'SSL.SVRCONN' did not specify a CipherSpec.
I'm assuming that I did not specify the parameters correctly in MQ/Explorer.
I have set both the "Trusted Certificate Store" and the "Personal Certificate Store" to point to the certificate repository on the windows system, which is:
C:\akey\key.kdb
I also set the "SSL CipherSpec" to DES_SHA_EXPORT, which is what I have set on SVRCONN channel on the server side.
Should I be putting the certificate names somewhere ?
I have ibmwebspheremq<qmname> on the server and ibmwebspheremq<userid> on the client side.
Anything else I may have forgotten ?
Back to top
View user's profile Send private message
mqjeff
PostPosted: Thu Dec 01, 2011 10:35 am    Post subject: Reply with quote

Grand Master

Joined: 25 Jun 2008
Posts: 17447

see the bottom half of this page.

Notice that little bitty ".jks".
Back to top
View user's profile Send private message
pfarrel
PostPosted: Mon Dec 05, 2011 2:48 am    Post subject: Reply with quote

Centurion

Joined: 16 Mar 2004
Posts: 120
Location: Kansas City

Thanks for the response. I had created a key.kdb on my windows system. I now have both a key.kdb and a key.jks. MQ/Explorer now works. I followed most of the instruction in your link, but there is one part I didn't do, and MQ/Explorer seems to work without it.
I didn't create a client channel definition ( and therefore didn't copy it to my windows system ). What does that do exactly, and why does MQ /Explorer work with out that step ?
Back to top
View user's profile Send private message
fjb_saper
PostPosted: Mon Dec 05, 2011 12:38 pm    Post subject: Reply with quote

Grand High Poobah

Joined: 18 Nov 2003
Posts: 20696
Location: LI,NY

pfarrel wrote:
Thanks for the response. I had created a key.kdb on my windows system. I now have both a key.kdb and a key.jks. MQ/Explorer now works. I followed most of the instruction in your link, but there is one part I didn't do, and MQ/Explorer seems to work without it.
I didn't create a client channel definition ( and therefore didn't copy it to my windows system ). What does that do exactly, and why does MQ /Explorer work with out that step ?

You want to client manual in the infocenter and it will answer your question.
_________________
MQ & Broker admin
Back to top
View user's profile Send private message Send e-mail
bruce2359
PostPosted: Mon Dec 05, 2011 1:29 pm    Post subject: Reply with quote

Poobah

Joined: 05 Jan 2008
Posts: 9399
Location: US: west coast, almost. Otherwise, enroute.

pfarrel wrote:
...why does MQ /Explorer work with out that step ?

Does your SVRCONN definition specify SSLCAUTH(REQUIRED) or SSLCAUTH(OPTIONAL)?
_________________
I like deadlines. I like to wave as they pass by.
ב''ה
Lex Orandi, Lex Credendi, Lex Vivendi. As we Worship, So we Believe, So we Live.
Back to top
View user's profile Send private message
pfarrel
PostPosted: Tue Dec 06, 2011 4:04 am    Post subject: Reply with quote

Centurion

Joined: 16 Mar 2004
Posts: 120
Location: Kansas City

I have SSLCAUTH(REQUIRED).
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » IBM MQ Security » SSL Connection with MQ/Explorer
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.