How to configure Connection Manager via ONSOCSSL?
Posted in 2009
Topics: High Availability & Replication, Networking & sqlhosts Configuration, Clustering, Grid & MACH11
I have configured two records at $INFORMIXSQLHOSTS file:
myserv_ssl1 onsocssl myserv sqlexec-ssl1
myserv_oltp_ssl onsocssl myserv sqlexec-ssl3
Connection manager has name cm_myserv, as configured at
$INFORMIXDIR/etc/cmsm_myserv.cfg file.
NAME cm_myserv
SLA myserv_oltp_ssl=(myserv_ssl1)
FOC SDS+HDR+RSS,10
SLA_WORKERS 16
LOGFILE /opt/IBM/informix/tmp/cm_myserv.log
DEBUG 1
Next I created three keystores: myserv_ssl1.kdb, myserv_oltp_ssl.kdb,
client.kdb.
Next I created default certificates for myserv_ssl1.kdb and
myserv_oltp_ssl.kdb keystores.
Next I extracted certificates from myserv_ssl1.kdb and
myserv_oltp_ssl.kdb keystores to ascii files.
Next I added certificates from myserv_ssl1.kdb to myserv_oltp_ssl.kdb
and client.kdb keystores.
Next I added certificates from myserv_oltp_ssl.kdb to myserv_ssl1.kdb
and client.kdb keystores.
Then I started the server and run the two SQL-script to test. One for
direct connection to IDS, and next via CM.
Direct request to the server is successful, but through the CM request not
completed with message "errors 28014: Secure Sockets Layer error:
GSK_ERROR_SOCKET_CLOSED. "
Connection Manager logfile have the line at the end of file: "listener accept
failed: network error = -28014 GSK_ERROR_NO_CERTIFICATE"
Whats wrong in my configuration?
After testing I found out that there should be several prerequisites: Suppose that INFORMIXSERVER refers to the real server and CONNECTIONMNGR is a SLA in the configuration file Connection Manager 1) Keystore should be created at $INFORMIXDIR/ssl/$INFORMIXSERVER.kbd file Keystore has to be one only!! KDBNAME=$INFORMIXDIR/ssl/$INFORMIXSERVER.kbd gsk7capicmd_64 -keydb -create -db $KDBNAME ... 2) The configuration file $INFORMIXDIR/etc/connssl.cfg must refer to this repository: SSL_KEYSTORE_FILE $INFORMIXDIR/ssl/$INFORMIXSERVER.kbd SSL_KEYSTORE_STH $INFORMIXDIR/ssl/$INFORMIXSERVER.sth 3) Must be created two self-signed certificates both for IDS and CM. gsk7capicmd_64 -cert -create -db $KDBNAME -label $INFORMIXSERVER -default_cert yes ... gsk7capicmd_64 -cert -create -db $KDBNAME -label $CONNECTIONMNGR -default_cert yes ... I previously believed that the option "-default_cert" should be used only once within the repository, and tried to create multiple copies of keystore, this was my mistake. Again, keystore has to be one, then the problem will not happen. This is as true in the case when the server and CM are on the same server as well as in the case when they are on different servers.