Translating with DrWatson… this can take a few seconds the first time.
This is a genuine, complex translation. DrWatson protects commands, error codes, and log output while naturally translating the surrounding text. It’s translated once and saved.
A user had SSL enabled on the Informix server but couldn't get Windows clients to connect. Cesar outlined the CSDK steps (create a client KDB with gsk8capicmd, import the server's .cert, point SSL_KEYSTORE_FILE/SSL_KEYSTORE_STH in $INFORMIXDIR/etc/conssl.cfg at the .kdb/.sth, configure an onsocssl entry) plus the JDBC equivalent using keytool and the sslConnection property. The poster then hit GSK_ERROR_BAD_KEYFILE_PASSWORD / permission denied; after a note about needing read permissions, he found the real cause: on the server the keystore must be named after DBSERVERNAME (in $INFORMIXDIR/ssl), not an alias. Resolved.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
SERGIO PERES — — source: IIUG Forums & Mailing Lists
Hi,
I have configured SSL for my informix server, now I would like to configure my
clients to connect to him, but I am facing some problems. As I have windows
clients to connect to my database, I don't found some concrete
information/examples about how to do it.
Can someone help me please?
Thanks in advance,
SP
↪ replying to SERGIO PERES
CESAR MARTINS — — source: IIUG Forums & Mailing Lists
Hi Sergio,
For CSDK :
https://www.ibm.com/support/knowledgecenter/en/SSGU8G_12.1.0/com.ibm.sec.doc/ids
_ssl_003.htm
For JDBC :
https://www.ibm.com/support/knowledgecenter/en/SSGU8G_12.1.0/com.ibm.jdbc_pg.doc
/ids_jdbc_490.htm
for CSDK:
1) create a KDB file on your client host, in any folder accessible by your
user :
$ gsk8capicmd_64.exe -keydb -create -db client.kdb -pw myPass -type cms -stashWill be created four files : client.crl client.kdb client.rdb client.sth
2) Import into this KDB your *.cert file .
$ gsk8capicmd_64.exe -cert -add -db client.kdb -stashed -label your_label_cert
-file your_file.cert -format ascii
3) Into your client $INFORMIXDIR/etc , create the file conssl.cfg and set the
parameter to the kdb and sth files :
SSL_KEYSTORE_FILE c:\\\\temp\\\\ssl\\\\client.kdb
SSL_KEYSTORE_STH c:\\\\temp\\\\ssl\\\\client.sth
4) Configure your client to INFORMIXSERVER / onsocssl / PORT set in your
database (to ONSOCSSL listener configured) and test the connection...
For JDBC is similar steps but you need to use the "keytool.exe" java command
to create the %JAVA_HOME%/lib/security/jssecacerts .
Then you just set the java properties to enable the SSL :
properties.put("sslConnection", "true");
// if you save the jssecacerts in another place, you must inform :
System.setProperty("javax.net.ssl.trustStore","c:/temp/ssl/jssecacerts");
System.setProperty("javax.net.ssl.trustStorePassword","myPass");
Comments :
* Have sure your SSL listener is UP , with "onstat -g ntt" you are able to see
the port/onsocssl set .
* Have sure your SSL label certificate is set equal in the ONCONFIG and
imported correctly into .kdb file in $INFORMIXDIR/ssl (as far I remember, you
need to restart the instance to reload the .kdb certificate if you did any
change there)
Regards
Cesar
↪ replying to CESAR MARTINS
SERGIO PERES — — source: IIUG Forums & Mailing Lists
Thanks for your help, I am going to test it!
↪ replying to CESAR MARTINS
SERGIO PERES — — source: IIUG Forums & Mailing Lists
Hi Cesar,
I've follow your instructions and on server everything is fine, but from
clients I am receiving one error:
GSK_ERROR_BAD_KEYFILE_PASSWORD, 13 ISAM message: Permission denied
Is it needed to give some special permission?
Thanks for your help,
SP
↪ replying to SERGIO PERES
LUIS MARQUES — — source: IIUG Forums & Mailing Lists
Clients need to have read permission on the files configured in
SSL_KEYSTORE_FILE and SSL_KEYSTORE_STH .
↪ replying to LUIS MARQUES
SERGIO PERES — — source: IIUG Forums & Mailing Lists
Thanks for the reply,
My mistake was that I have used one alias for argument on gsk8capicmd for -db.
It seems to be necessary that argument is the same as DBSERVERNAME.
SP
↪ replying to SERGIO PERES
LUIS MARQUES — — source: IIUG Forums & Mailing Lists
Yes, on the server side, according to the documentation, the keystore file
must have the name DBSERVERNAME.kdb and be created in $INFORMIXDIR/ssl/ .
On the client side, the name and location can be defined in the
$INFORMIXDIR/conssl.cfg using the parameters SSL_KEYSTORE_FILE and
SSL_KEYSTORE_STH .
We use strictly necessary cookies to make this site work. With your
consent we’d also use optional cookies for analytics and marketing. You can accept all,
reject all, or choose. Read our Cookie Policy.