Skip to main content

How to Configure SSL for the MQSC Adapter - Middleware News

How to Configure SSL for the MQSC Adapter - Middleware News



The following procedures are designed to help you with configuring a Windows MQSeries Client to run with Secure Sockets Layer (SSL)-enabled MQSeries Server channels. The procedures describe configuration for one-way (Server) authentication.

Configuration is performed in the following steps:

* Set up the Queue Manager/Client to work without SSL.
* Add SSL to the configuration.
* Configure the MQSeries Client-Based Adapter properties for SSL.


Note

For more information, refer to IBM WebSphere MQ documentation. If you already have MQSeries client/server SSL working, you can go directly to the procedure for configuring the SSL properties in the adapter.

The following procedures assume that you are setting up a new Queue Manager. However, you can also apply these steps to existing Queue Managers.
To set up the Queue Manager/Client to work without SSL

1.
Create a Queue Manager named QM1, and define a listener on the required port.
2.

Define a SVRCONN channel TO.QM1.
3.

Define a CLNTCONN channel TO.QM1.

4.

Supply the name on the SVRCONN channel to which it will connect (TO.QM1), the transport type, the IP address/DNS name of the server, and the port number.

5.

Define a local queue on the target Queue Manager named TESTQUEUE, which can be used for testing the client connections.

6.

Copy the AMQCLCHL.TAB file from the server onto the client computer. (This file can be found in /var/mqm/qmgrs//@IPCC on most UNIX installations and /Program Files//qmgrs//@IPCC on most Windows installations.)
7.

On the client computer, set the following environment variables:
* MQCHLLIB=C:\sslclient\ssl\ (where MQCHLLIB is set to the path of the client channel table).
* MQCHLTAB=AMQCLCHL.TAB (where MQCHLTAB is set to the name of the client channel table).
Aa754431.note(en-US,BTS.10).gifNote
There are defaults for these environment variables if you want to use them. See the WebSphere MQ Client manual for more information.

8.

Test that the client connection works by running amqsputc.exe on your BizTalk Server computer: amqsputc.exe TESTQUEUE.

To add SSL to the configuration
================================

1.

Add the certificate to the Queue Manager’s store (using Internet Explorer/the MQSeries user interface or amqmcert on Windows, or gsk6ikm or gsk6cmd on UNIX).
2.

Alter the SVRCONN channel so the SSLCIPH is set (for example, to NULL_MD5) and set SSLCAUTH to OPTIONAL.
Aa754431.note(en-US,BTS.10).gifNote
SSLCAUTH is required for two-way authentication (client/server).

3.

Alter the CLNTCONN channel so the SSLCIPH is set to the same as the SVRCONN channel (for example, to NULL_MD5).
4.

Copy the new AMQCLCHL.TAB file from the server onto the client computer; the changes made for SSL can be picked up.
5.

On the Windows client computer, ensure that the CA certificates are in the system key store (you can do this from Internet Explorer) and if they are not, import them into it (again, using Internet Explorer).
6.

Export the following environment variable to specify the location and name of the client key store: set MQSSLKEYR=C:\sslclient\ssl\key.

Note
The key store must have the file name extension .sto and the environment variable must not specify it.

7.

When you have the required CA certificates in the system store, you can set up a client key store.

1. List the certificates in the system CA store: amqmcert -l -k ca and note the number(s) of the required CA certificate(s)

2. Add the certificates to the client store: amqmcert -a (certificate_number), where (certificate_number) is the number of each required certificate.
8.

Test that the SSL Client connections work by using the amqsputc sample program and the test queue that you set up previously.

Note

You do not actually have to import CA certificates into the Windows system store before; for example, you can import the certificates to the client certificate store straight from a file. See the IBM MQSeries System Admin guide for information about amqmcert.

When the MQSeries Client-to-MQSeries Queue Manager SSL is working, the adapter can be configured on both receive locations and send ports to use SSL. The property values that were used in the test must be specified in the adapter configuration. The following adapter properties are relevant to both send port and receive locations:

SSL Cipher Specification defines a single CipherSpec for an SSL connection that will be used by the endpoint configured in the adapter. Both ends of a WebSphere MQ SSL channel definition must include the attribute, and the value specified here should match the name that was specified on the server end of the channel. The value is a string with a maximum length of 32 characters.

SSL Peer Name is used to check the distinguished name (also known as DN) of the certificate from the peer queue manager or client at the other end of a WebSphere MQ channel. If the distinguished name received from the peer does not match this value, the channel does not start.

Comments

adsrerrapop

Popular posts from this blog

Troubleshooting Java/JMS SSL Configurations - Middleware News

 This document is intended to help diagnose WebSphere MQ V7 Java™ or JMS SSL setup errors. It lists most of the common configuration errors that can cause an SSL connection from a Java/JMS client to a queue manager to fail, and gives the course of action to resolve the problem. In each case the error can be diagnosed by a combination of the error seen in the client log - either a console output, trace file or SystemOut.log file - and the queue manager's error logs. The document is quite long, so the easiest way to find the potential error is to search for one of the errors seen in this list, then filter this list using the error from the opposite end of the channel. All cases here assume that 2-way authentication is being attempted (SSLCAUTH set to REQUIRED on the queue manager's SVRCONN channel). This is the default, and the errors are very similar for 1-way authentication (SSLCAUTH set to OPTIONAL). Symptom Instructions on collecting documentation...

Using telnet to test connectivity between IBM Websphere MQ Client and MQ server - Middleware News

You are having trouble connecting a WebSphere MQ client to a MQ server, receiving errors that you can not connect to the MQ queue manager. One of the first things to determine is if the two machines can communicate, and using the telnet tool is one way to accomplish it. Symptom Receiving errors which state that a queue manager is not found or not available. Connection errors. For example: AMQ9213, AMQ9524, AMQ9202 or AMQ9508 or MQRC =2059 0x0000080b MQRC_Q_MGR_NOT_AVAILABLE. Please note, this is by no means an exclusive list of errors related to this type a problem but just a sample of some of the more common error messages and codes that might occur. Cause One possible cause is that the two machines can not communicate. May be the IP address or hostname was not properly specified by the MQ client. The port number might be incorrect. A queue manager is not running at the desired host. The queue manager could be running, but the corresponding listener is not runnin...

IBM Websphere MQ interview Questions Part 5

MQ Series: - It is an IBM web sphere product which is evolved in 1990’s. MQ series does transportation from one point to other. It is an EAI tool (Middle ware) VERSIONS:-5.0, 5.1, 5.3, 6.0, 7.0(new version). The currently using version is 6.2 Note: – MQ series supports more than 35+ operating systems. It is platform Independent. For every OS we have different MQ series software’s. But the functionality of MQ series Default path for installing MQ series is:- C: programfiles\BM\clipse\SDK30 C: programfiles\IBM\WebsphereMQ After installation it will create a group and user. Some middleware technologies are Tibco, SAP XI. MQ series deals with two things, they are OBJECTS, SERVICES. In OBJECTS we have • QUEUES • CHANNELS • PROCESS • AUTHENTICATION • QUERY MANAGER. In SERVICES we have LISTENERS. Objects: – objects are used to handle the transactions with the help of services. QUEUE MANAGER maintains all the objects and services. QUEUE: – it is a database structure ...