onsocssl problem
Posted in 2018
Topics: Server Administration, Security, Permissions & Auditing, Networking & sqlhosts Configuration
Hi, I am trying to test SSL connection over informix, I have create the certificate: gsk8capicmd_64 -keydb -create -db $INFORMIXDIR/ssl/$SERVER_NAME.kdb -pw $MYPASSWORD -type cms -stash gsk8capicmd_64 -cert -create -db $INFORMIXDIR/ssl/$SERVER_NAME.kdb -pw ${MYPASSWORD} -label ${SERVER_NAME}_label -dn "CN=`hostname`" -size ${KEYSIZE} -default_cert yes -expire ${EXPIRE} The ONCONFIG variable: SSL_KEYSTORE_LABEL ${SERVER_NAME}_label Connection parameter: NETTYPE socssl,1,20,NET my sqlhosts: srvlbdtrial_ssl onsocssl srvlbdtrial s1527_tcp When I try to start my server it returns: Initializing ASF...oninit: Fatal error in initializing ASF with 'ASF_INIT_DATA' flags; asfcode = '-28014'. FAILED And on log: 14:26:24 IBM Global Security Kit (GSKit) version 8.0.50.88. 14:26:24 Secure Sockets Layer error: GSK_ERROR_BAD_KEYFILE_LABEL. am I missing something? or doing some mistake? Thanks for any help, SP
I have seen my mistake was the name on ONCONFIG.
But now when I try to connect over dbaccess I receive this error:
28014: Secure Sockets Layer error: GSK_KEYRING_OPEN_ERROR.No such file or directory
Is anything wrong with my settings?
Thanks for any help,
SP
You also need to setup the client side. Check the documentation: https://www.ibm.com/support/knowledgecenter/en/SSGU8G_12.1.0/com.ibm.sec.doc/ids _ssl_003.htm You need to create a keystore for the client, extract the certificate from the server keystore and import it to the client keystore and then configure the client to use the proper keystore.