IBM Support

Open Mic Replay: SSL and TLS in WebSphere MQ

Webcasts


Abstract

This session is for WebSphere MQ users who use SSL or TLS to secure their channels. It covers an overview of terminology, certificate administration (GSKit, Java, RACF and DCM) and problem diagnosis. The session covers Windows, UNIX, IBM i, z/OS, JMS and Java (including JSSE).

Content

Open Mic sessions are conducted in a question and answer format. The table below provides a time index (minutes:seconds) to the recording and describes the questions or topics discussed. You can fast forward to any question using the time index, a table containing the panel of experts is also included.


To play or download the audio of this Open Mic session, see the Audio Section of this document.

See the Related Information Section of this document for a list of documents referenced during the presentation.




Open Mic session
29 April 2010 - 11:00 a.m. - 12:00 p.m. EDT

TimeQuestions asked
00:00Silence
00:00General introduction
03:55Technical introduction
05:21What are CA certificates, signer certificates, personal certificates, client certificates and server certificates?
08:31What is a certificate chain and how do I view it?
17:51How do I renew an expired certificate?
21:50How do I make sure that SSL/TLS is set up correctly?
36:12What has changed in MQ SSL/TLS since version 5.3?
43:41Must the environment variable MQSSLKEYR be always defined? Does it apply to all MQ versions and platforms?
44:57Does SSL work for only point to point channels, or can it work in a clustered environment? If yes, how do you handle keystore and personal certificate in a clustered environment?
45:42On Windows, we seem to require having the full certificate chain of certificates we want to authenticate, whereas on Unix it appears the root certificate CA is sufficient to authenticate. Is this difference in behavior expected between the two platforms?
47:42We have queue managers on AIX that were installed without the SSL components and we moved them up to 6.0.2.6 and also added some additional patches to them. What is the best way to get them to use SSL?
51:41When using the MQCONNX verb to connect a WMQ client to the server, what do I need to specify in the options for the key database or does MQSSLKEYR work?
53:15For slide 36, how do I manipulate the OCSPs in MQ V7.0.1 to be active or not?
56:20Closing remarks
57:19End of Call

Panel of Experts:
Alex FehnersWebSphere MQ New Market Reach Development
Andrew AkehurstWebSphere MQ Distributed L3 Service
Calista StevensWebSphere MQ System i Level 2 Support
Jonathan RumseyLead System i Developer WebSphere MQ
Mike HoranWebSphere MQ Software Developer
Rhys FrancisWebSphere MQ for z/OS Level 3
Tameka WoodyWebSphere MQ Windows and System i Level 2 Support
Mark WomackWebSphere MQ z/OS Level 2 Support - TSANet PgmMgr
Tiffanie PearsonWebSphere MQ Unix and VMS Level 2 Support


Presentation

WSTE-04292010-OpenMic-SSLandTLSinWebSphereMQ-Pearson.pdf

Get Adobe Reader to view PDF

Audio

Click on Download Audio to play the recording of this 57 minutes conference call (6.0MB - MP3 format). Right-click and select Save As to store the file on your local computer for later playback. Remember that you can fast forward to any question using the time index.

[{"Product":{"code":"SSFKSJ","label":"WebSphere MQ"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"SSL","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF012","label":"IBM i"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"},{"code":"PF035","label":"z\/OS"}],"Version":"8.0;7.1;7.0.1;7.0;6.0.2;6.0.1;6.0","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Product Synonym

WMQ MQ

Document Information

Modified date:
17 June 2018

UID

swg27018213