RE: LDAP Key Store Password and GSK7capicmd Password
Gregory Mendes <[email protected]>
| Newsgroups | gmane.comp.sysutils.tivoli.general,gmane.comp.sysutils.tivoli.tme10 |
|---|---|
| Message-ID | <[email protected]> |
Hey Toben, Here's the problem. By default the configuration for LDAP at the hub_TEMS creates a CA called IBM_Tivoli_Monitoring_Certificate that is set to the default private key CA (!-*). When I import the CA certificate that the customer wants to use, it's listed in the keyfile.kdb but I can make it the default. It give me the error GSKKM_ERR_KEYREC_PRIVATE_KEY_NULL when trying to run the gsk7capicmd -cert -setdefault -db /opt/IBM/ITM/keyfiles/keyfile.kdb -label "goes CA". It's really making me want to shoot a round through the screen. :) Regards, Gregory R. Mendes Tivoli Architect/Tools Specialist Mendes, Inc. Tivoli Monitoring 6.2.3 Certified 770-317-8593 Date: Wed, 20 Mar 2013 18:32:40 -0500 Subject: Re: [TME10] LDAP Key Store Password and GSK7capicmd Password From: [email protected] To: [email protected] Private keys, keystores, password encryption of said keystores and/or keys: all interchangable relative to OS. But I hear you, not apt in the perfect sense for Linux On Mar 20, 2013 4:34 PM, "[email protected]" <[email protected]> wrote: So if you are talking about creating a new keystore, then you can give it any password you want and that password has nothing to do with SSL encryption at all--it just serves as your credential to open the keystore database (*.kdb) file. Once you have a keystore database opened, you can then import/export certificates of types both "personal" and "signer" to/from it. Sometimes these certificates themselves were password protected when they were exported, and so to import them into your keystore you'll need to have the password used when they were exported. I know that isn't an explicit answer to the error you're seeing below, but I'm just providing enough info to get moving in a progressive direction. Also, the attached file, while germane on its surface to MS's IE, has some good info int he 7 sections at the beginning that can shed some light on the relationships and concepts here. Toben On Wed, Mar 20, 2013 at 2:07 PM, Gregory Mendes <[email protected]> wrote: Hello All, Are these two passwords the same? So, when I configure the h_tems for LDAP support it asks me for LDAP Key store and I give it a password. Should this password be the IBM61TIV or can you make it anything? Or, does this password need to be the same for both the LDAP configuration and the CA certificate install to the keyfile.kdb? I get this error in my TEMS logfile: LDAP client is Success. LDAP SSL initialization (113), SSL failure reason code (102): LDP1_Keyring /opt/IBM/ITM/keyfiles, password xxxxxxxx. Any ideas? Regards, Gregory R. Mendes Tivoli Architect/Tools Specialist Mendes, Inc. Tivoli Monitoring 6.2.3 Certified 770-317-8593 _______________________________________________ TME10 mailing list [email protected] Unsubscribe:[email protected] -- "Sometimes I think that's the only right thing to do: To dream. to live in the world of dreams. But it doesn't last forever--wakefulness always comes to take me back..." _______________________________________________ TME10 mailing list [email protected] Unsubscribe:[email protected] _______________________________________________ TME10 mailing list [email protected] Unsubscribe:[email protected]