How to configure Connection Manager for a protocol onsocssl?
Posted in 2009
Poster couldn't get Connection Manager working over the onsocssl (SSL) protocol on IDS 11.50.FC4W1 / CSDK 3.50.xC4 on SLES 10: direct dbaccess connections worked, but connecting via an SLA logged "listener accept failed: network error = -28014 GSK_ERROR_NO_CERTIFICATE". He later answered himself: use a single keystore ($INFORMIXDIR/ssl/$INFORMIXSERVER.kbd, referenced by connssl.cfg via SSL_KEYSTORE_FILE/STH) holding two self-signed certs, one labelled for the server and one for the CM, each created with -default_cert yes. His error had been creating separate keystore copies.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Server Administration, Clustering, Grid & MACH11
Hello, gurus! Does anyone know how to configure Connection Manager for a protocol onsocssl? Dbaccess has established connection directly to the server for a protocol onsocssl without any problems. When CM has started, it started succesfully, but when I want to connect via SLA, CM outputs the message "listener accept failed: network error = -28014 GSK_ERROR_NO_CERTIFICATE" to logfile. Regards, Victor Vat
victor16 wrote: > Hello, gurus! > > Does anyone know how to configure Connection Manager for a protocol > onsocssl? Dbaccess has established connection directly to the server > for a protocol onsocssl without any problems. When CM has started, it > started succesfully, but when I want to connect via SLA, CM outputs > the message "listener accept failed: network error = -28014 > GSK_ERROR_NO_CERTIFICATE" to logfile. > > Regards, > Victor Vat Hi, Can you confirm the exact versions of IDS and CSDK that you are using??
On 8 июл, 16:05, theBP <th...@Usenet-News.Net> wrote: > victor16 wrote: > > Hello, gurus! > > > Does anyone know how to configure Connection Manager for a protocol > > onsocssl? Dbaccess has established connection directly to the server > > for a protocol onsocssl without any problems. When CM has started, it > > started succesfully, but when I want to connect via SLA, CM outputs > > the message "listener accept failed: network error = -28014 > > GSK_ERROR_NO_CERTIFICATE" to logfile. > > > Regards, > > Victor Vat > > Hi, > > Can you confirm the exact versions of IDS and CSDK that you are using?? IDS=11.50.FC4W1 OS=SUSE SLES 10 SP 2 CSDK=3.50.xC4, April 2009
victor16 wrote: > On 8 июл, 16:05, theBP <th...@Usenet-News.Net> wrote: >> victor16 wrote: >>> Hello, gurus! >>> Does anyone know how to configure Connection Manager for a protocol >>> onsocssl? Dbaccess has established connection directly to the server >>> for a protocol onsocssl without any problems. When CM has started, it >>> started succesfully, but when I want to connect via SLA, CM outputs >>> the message "listener accept failed: network error = -28014 >>> GSK_ERROR_NO_CERTIFICATE" to logfile. >>> Regards, >>> Victor Vat >> Hi, >> >> Can you confirm the exact versions of IDS and CSDK that you are using?? > > IDS=11.50.FC4W1 > OS=SUSE SLES 10 SP 2 > CSDK=3.50.xC4, April 2009 Give me a bit of time, and I will provide a complete set of details (need to make it all "non-specific"). I may be able to provide a script
On 8 июл, 17:42, theBP <th...@Usenet-News.Net> wrote: > victor16 wrote: > > On 8 июл, 16:05, theBP <th...@Usenet-News.Net> wrote: > >> victor16 wrote: > >>> Hello, gurus! > >>> Does anyone know how to configure Connection Manager for a protocol > >>> onsocssl? Dbaccess has established connection directly to the server > >>> for a protocol onsocssl without any problems. When CM has started, it > >>> started succesfully, but when I want to connect via SLA, CM outputs > >>> the message "listener accept failed: network error = -28014 > >>> GSK_ERROR_NO_CERTIFICATE" to logfile. > >>> Regards, > >>> Victor Vat > >> Hi, > > >> Can you confirm the exact versions of IDS and CSDK that you are using?? > > > IDS=11.50.FC4W1 > > OS=SUSE SLES 10 SP 2 > > CSDK=3.50.xC4, April 2009 > > Give me a bit of time, and I will provide a complete set of details (need to make it all "non-specific"). > > I may be able to provide a script- Скрыть цитируемый текст - > > - Показать цитируемый текст - Thanx in advance. I just want to point out that I have tried to create certificates for the Connection Manager as similar for IDS.
After testing I found out that there should be several prerequisites: Suppose that INFORMIXSERVER refers to the real server and CONNECTIONMNGR is a SLA in the configuration file Connection Manager 1) Keystore should be created at $INFORMIXDIR/ssl/$INFORMIXSERVER.kbd file Keystore has to be one only!! KDBNAME=$INFORMIXDIR/ssl/$INFORMIXSERVER.kbd gsk7capicmd_64 -keydb -create -db $KDBNAME ... 2) The configuration file $INFORMIXDIR/etc/connssl.cfg must refer to this repository: SSL_KEYSTORE_FILE $INFORMIXDIR/ssl/$INFORMIXSERVER.kbd SSL_KEYSTORE_STH $INFORMIXDIR/ssl/$INFORMIXSERVER.sth 3) Must be created two self-signed certificates both for IDS and CM. gsk7capicmd_64 -cert -create -db $KDBNAME -label $INFORMIXSERVER -default_cert yes ... gsk7capicmd_64 -cert -create -db $KDBNAME -label $CONNECTIONMNGR -default_cert yes ... I previously believed that the option "-default_cert" should be used only once within the repository, and tried to create multiple copies of keystore, this was my mistake. Again, keystore has to be one, then the problem will not happen. This is as true in the case when the server and CM are on the same server as well as in the case when they are on different servers. On 8 июл, 17:51, victor16 <vv63...@gmail.com> wrote: > On 8 июл, 17:42, theBP <th...@Usenet-News.Net> wrote: > > > > > > > victor16 wrote: > > > On 8 июл, 16:05, theBP <th...@Usenet-News.Net> wrote: > > >> victor16 wrote: > > >>> Hello, gurus! > > >>> Does anyone know how to configure Connection Manager for a protocol > > >>> onsocssl? Dbaccess has established connection directly to the server > > >>> for a protocol onsocssl without any problems. When CM has started, it > > >>> started succesfully, but when I want to connect via SLA, CM outputs > > >>> the message "listener accept failed: network error = -28014 > > >>> GSK_ERROR_NO_CERTIFICATE" to logfile. > > >>> Regards, > > >>> Victor Vat > > >> Hi, > > > >> Can you confirm the exact versions of IDS and CSDK that you are using?? > > > > IDS=11.50.FC4W1 > > > OS=SUSE SLES 10 SP 2 > > > CSDK=3.50.xC4, April 2009 > > > Give me a bit of time, and I will provide a complete set of details (need to make it all "non-specific"). > > > I may be able to provide a script- Скрыть цитируемый текст - > > > - Показать цитируемый текст - > > Thanx in advance. > I just want to point out that I have tried to create certificates for > the Connection Manager as similar for IDS.- Скрыть цитируемый текст - > > - Показать цитируемый текст -