How to config SSL
Posted in 2009
Topics: General Discussion
Do anybody know how to config the SSL communication between the client and server? thanks
I think these steps should be there in IDS documentation as well
Steps to setup SSL
----------------------
ONCONFIG
Located in $INFORMIXDIR/etc
Configure server name and aliases
DBSERVERNAME lenexa_on
DBSERVERALIASES menlo_on,portland_on
SSL encryption/decryption operations are performed on Encrypt VP.
Depending upon load on system, configure Encrypt VPs via VPCLASS parame=
ter.
If VPCLASS is not configured, server will start one Encrypt VP.
VPCLASS encrypt,num=3D3
Depending upon load on system, configure poll threads for SSL connectio=
n
via NETTYPE parameter.
If poll threads are not configured, server will start one poll thread.
NETTYPE socssl,3,50,NET
Configure label for server digital certificate in keystore.
If not configured, the server will use the default label in keystore fo=
r
SSL communication.
SSL_KEYSTORE_LABEL ssltestlabel
CONSSL.CFG - For SQLI clients only
Located in $INFORMIXDIR/etc
Configure fully qualified filename of client keystore
SSL_KEYSTORE_FILE /work/keystores/clikeydb.kdb
Configure fully qualified filename of client stash file
SSL_KEYSTORE_STH /work/keystores/clikeydb.sth
If conssl.cfg does not exist or if any of above parameters are not
configured, the client keystore and stash file will default to:
$INFORMIXDIR/etc/client.kdb and $INFORMIXDIR/etc/client.sth
SQLHOSTS
Located in $INFORMIXDIR/etc or configured via INFORMIXSQLHOSTS environm=
ent
New communication protocols
drsocssl - protocol for supporting SSL communication with DRDA clients
onsocssl/olsocssl - protocol for supporting SSL communication with SQLI=
clients and between servers in ISTAR, HDR, ER, SDS/RSS
lenexa_on onsoctcp pinchy lenexa_serv
menlo_on onsocssl pinchy menlo_serv
portland_on drsocssl pinchy portland_serv
SERVER KEYSTORE
Location and name of server keystore and its password stash file is
predefined
$INFORMIXDIR/ssl/servername.kdb
$INFORMIXDIR/ssl/servername.sth
servername is value of DBSERVERNAME onconfig parameter
Commands for creating keystore and self-signed test certificate using
non-java command line utility (gsk7capicmd/gsk7capicmd_64):
gsk7capicmd -keydb -create -db lenexa_on.kdb -pw snoopy -type cms -stas=
h
gsk7capicmd -cert -create -db lenexa_on.kdb -pw snoopy -label ssltestla=
bel
-dn "CN=3Dlenexa.ibm.com,O=3Dibm,C=3DUS" -size 1024 -default_cert yes
Command for exporting certificate to ascii file (to be imported to clie=
nt
keystore):
gsk7capicmd -cert -extract -db lenexa_on.kdb -format ascii -label
ssltestlabel -pw snoopy -target ssltestlabel.cert
Change permissions on keystore and stash file to 600/informix:informix
CLIENT KEYSTORE
Commands for creating keystore and importing server certificate using
non-java command line utility (gsk7capicmd/gsk7capicmd_64):
gsk7capicmd -keydb -create -db clikeydb.kdb -pw snoopy -type cms -stash=
gsk7capicmd -cert -add -db clikeydb.kdb -pw snoopy -label ssltestlabel
-file ssltestlabel.cert -format ascii
Change the permissions on the keystore and stash files to
664/informix:informix. (In an INFORMIXDIR that contains CSDK or I-Conne=
ct,
you should have public read access; if the INFORMIXDIR only contains ID=
S,
you might use just 600 or 640 permissions.)
INITIALIZE SERVER
Move server and client keystores to sepcified location and initialize
server.
All communication between client and server will be encrypted using SSL=
protocol.
=
From: "CHUAN LU" <luchuan114@sina.com> =
=
To: ids@iiug.org =
=
Date: 07/28/2009 08:39 AM =
=
Subject: How to config SSL [16512] =
=
Sent by: ids-bounces@iiug.org =
=
Do anybody know how to config the SSL communication between the client =
and
server? thanks
***********************************************************************=
********
Forum Note: Use "Reply" to post a response in the discussion forum.
=