|
RSS Feed - WebSphere MQ Support
|
RSS Feed - Message Broker Support
|
 |
|
Broker 7 Mutual Authentication SSL |
« View previous topic :: View next topic » |
Author |
Message
|
matuwe |
Posted: Thu Jul 24, 2014 1:08 pm Post subject: Broker 7 Mutual Authentication SSL |
|
|
 Master
Joined: 05 Dec 2007 Posts: 296
|
Hi I have enabled SSL on my broker. I can get my service consumers calling me via HTTPS.. But now I have to enable mutual authentication.. I loaded the certificate provided from security into broker cert. 2. Created a self signed cert on the broker and installed it on my local, 3. then created a self signed cert on my local and loaded it on my broker. enabled client auth on the broker and tested successful..
Can I kindly confirm if this is the right way to enable mutual authentication? do I need to get self signed certificate from all my service consumers and provide them with my self signed cert? |
|
Back to top |
|
 |
fjb_saper |
Posted: Thu Jul 24, 2014 3:20 pm Post subject: Re: Broker 7 Mutual Authentication SSL |
|
|
 Grand High Poobah
Joined: 18 Nov 2003 Posts: 20756 Location: LI,NY
|
matuwe wrote: |
Can I kindly confirm if this is the right way to enable mutual authentication? do I need to get self signed certificate from all my service consumers and provide them with my self signed cert? |
You should be using CA signed for this and not self signed certs...
Note that if they are all internal you probably already have an internal CA authority
Have fun  _________________ MQ & Broker admin |
|
Back to top |
|
 |
mqjeff |
Posted: Fri Jul 25, 2014 5:15 am Post subject: |
|
|
Grand Master
Joined: 25 Jun 2008 Posts: 17447
|
It doesn't really matter who signs the certificates.
Mutual Authentication means that both sides have personal certificates, and that both sides verify that they trust the signer of the other side's certificate.
This could be self-signed, CA signed, signed by different CAs, etc. |
|
Back to top |
|
 |
matuwe |
Posted: Mon Jul 28, 2014 6:47 am Post subject: |
|
|
 Master
Joined: 05 Dec 2007 Posts: 296
|
Thanks so much for the response. I will test with self signed cert from SOAPUI, then test with CA cert between systems.
Your feedback was very helpful.. Very much appreciated.
 |
|
Back to top |
|
 |
|
|
 |
|
Page 1 of 1 |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|
|
|