| Newsgroups |
gmane.comp.sysutils.tivoli.general |
| Message-ID |
<CAMzJ2PrP9oAQZQ9RzT8kzhxAVHjX+1DnjUW-F_Z=d-0xuU_Z=Q__13242.4449701377$1363829060$gmane$org@mail.gmail.com> |
Very interesting and wholly unique to me. I have t declare defeat and
depart the field at this juncture, however I look forward to seeng what the
eventual solution is....and this is assuming it is other than a rebuild of
the keystore i. A different order...as if that should eve.atter considering
that there should be parity among certs as a group in the keystore db.
On Mar 20, 2013 7:35 PM, "Gregory Mendes" <[email protected]>
wrote:
> Hey Toben,
>
> Here's the problem. By default the configuration for LDAP at the hub_TEMS
> creates a CA called IBM_Tivoli_Monitoring_Certificate that is set to the
> default private key CA (!-*). When I import the CA certificate that the
> customer wants to use, it's listed in the keyfile.kdb but I can make it the
> default. It give me the error GSKKM_ERR_KEYREC_PRIVATE_KEY_NULL when
> trying to run the gsk7capicmd -cert -setdefault -db
> /opt/IBM/ITM/keyfiles/keyfile.kdb -label "goes CA". It's really making me
> want to shoot a round through the screen. :)
>
> Regards,
>
> Gregory R. Mendes
> Tivoli Architect/Tools Specialist
> Mendes, Inc.
> Tivoli Monitoring 6.2.3 Certified
> 770-317-8593
>
>
> ------------------------------
> Date: Wed, 20 Mar 2013 18:32:40 -0500
> Subject: Re: [TME10] LDAP Key Store Password and GSK7capicmd Password
> From: [email protected]
> To: [email protected]
>
> Private keys, keystores, password encryption of said keystores and/or
> keys: all interchangable relative to OS. But I hear you, not apt in the
> perfect sense for Linux
> On Mar 20, 2013 4:34 PM, "[email protected]" <
> [email protected]> wrote:
>
> So if you are talking about creating a new keystore, then you can give it
> any password you want and that password has nothing to do with SSL
> encryption at all--it just serves as your credential to open the keystore
> database (*.kdb) file. Once you have a keystore database opened, you can
> then import/export certificates of types both "personal" and "signer"
> to/from it. Sometimes these certificates themselves were password
> protected when they were exported, and so to import them into your keystore
> you'll need to have the password used when they were exported.
>
> I know that isn't an explicit answer to the error you're seeing below, but
> I'm just providing enough info to get moving in a progressive direction.
> Also, the attached file, while germane on its surface to MS's IE, has some
> good info int he 7 sections at the beginning that can shed some light on
> the relationships and concepts here.
>
> Toben
>
> On Wed, Mar 20, 2013 at 2:07 PM, Gregory Mendes <
> [email protected]> wrote:
>
> Hello All,
>
> Are these two passwords the same?
>
> So, when I configure the h_tems for LDAP support it asks me for LDAP Key
> store and I give it a password. Should this password be the IBM61TIV or
> can you make it anything? Or, does this password need to be the same for
> both the LDAP configuration and the CA certificate install to the
> keyfile.kdb?
>
> I get this error in my TEMS logfile:
>
> LDAP client is Success.
> LDAP SSL initialization (113), SSL failure reason code (102):
> LDP1_Keyring /opt/IBM/ITM/keyfiles, password xxxxxxxx.
>
> Any ideas?
>
> Regards,
>
> Gregory R. Mendes
> Tivoli Architect/Tools Specialist
> Mendes, Inc.
> Tivoli Monitoring 6.2.3 Certified
> 770-317-8593
>
>
> _______________________________________________
> TME10 mailing list
> [email protected]
> Unsubscribe:[email protected]
>
>
>
>
> --
> "Sometimes I think that's the only right thing to do:
> To dream. to live in the world of dreams.
> But it doesn't last forever--wakefulness always comes to take me back..."
>
>
> _______________________________________________ TME10 mailing list
> [email protected] Unsubscribe:[email protected]
>
> _______________________________________________
> TME10 mailing list
> [email protected]
> Unsubscribe:[email protected]
>
>
_______________________________________________
TME10 mailing list
[email protected]
Unsubscribe:[email protected]