RE: LDAP Key Store Password and GSK7capicmd Password

"[email protected]" <[email protected]>
Newsgroups gmane.comp.sysutils.tivoli.general
Message-ID <CAMzJ2PrP9oAQZQ9RzT8kzhxAVHjX+1DnjUW-F_Z=d-0xuU_Z=Q__13242.4449701377$1363829060$gmane$org@mail.gmail.com>
Very interesting and wholly unique to me.  I have t declare defeat and
depart the field at this juncture, however I look forward to seeng what the
eventual solution is....and this is assuming it is other than a rebuild of
the keystore i. A different order...as if that should eve.atter considering
that there should be parity among certs as a group in the keystore db.
On Mar 20, 2013 7:35 PM, "Gregory Mendes" <[email protected]>
wrote:

>  Hey Toben,
>
> Here's the problem.  By default the configuration for LDAP at the hub_TEMS
> creates a CA called IBM_Tivoli_Monitoring_Certificate that is set to the
> default private key CA (!-*).  When I import the CA certificate that the
> customer wants to use, it's listed in the keyfile.kdb but I can make it the
> default.  It give me the error GSKKM_ERR_KEYREC_PRIVATE_KEY_NULL when
> trying to run the gsk7capicmd -cert -setdefault  -db
> /opt/IBM/ITM/keyfiles/keyfile.kdb -label "goes CA".  It's really making me
> want to shoot a round through the screen.  :)
>
> Regards,
>
> Gregory R. Mendes
> Tivoli Architect/Tools Specialist
> Mendes, Inc.
> Tivoli Monitoring 6.2.3 Certified
> 770-317-8593
>
>
> ------------------------------
> Date: Wed, 20 Mar 2013 18:32:40 -0500
> Subject: Re: [TME10] LDAP Key Store Password and GSK7capicmd Password
> From: [email protected]
> To: [email protected]
>
> Private keys, keystores, password encryption of said keystores and/or
> keys: all interchangable relative to OS.  But I hear you, not apt in the
> perfect sense for Linux
> On Mar 20, 2013 4:34 PM, "[email protected]" <
> [email protected]> wrote:
>
> So if you are talking about creating a new keystore, then you can give it
> any password you want and that password has nothing to do with SSL
> encryption at all--it just serves as your credential to open the keystore
> database (*.kdb) file.  Once you have a keystore database opened, you can
> then import/export certificates of types both "personal" and "signer"
> to/from it.  Sometimes these certificates themselves were password
> protected when they were exported, and so to import them into your keystore
> you'll need to have the password used when they were exported.
>
> I know that isn't an explicit answer to the error you're seeing below, but
> I'm just providing enough info to get moving in a progressive direction.
> Also, the attached file, while germane on its surface to MS's IE, has some
> good info int he 7 sections at the beginning that can shed some light on
> the relationships and concepts here.
>
> Toben
>
> On Wed, Mar 20, 2013 at 2:07 PM, Gregory Mendes <
> [email protected]> wrote:
>
>  Hello All,
>
> Are these two passwords the same?
>
> So, when I configure the h_tems for LDAP support it asks me for LDAP Key
> store and I give it a password.  Should this password be the IBM61TIV or
> can you make it anything?  Or, does this password need to be the same for
> both the LDAP configuration and the CA certificate install to the
> keyfile.kdb?
>
> I get this error in my TEMS logfile:
>
> LDAP client is Success.
> LDAP SSL initialization (113), SSL failure reason code (102):
> LDP1_Keyring /opt/IBM/ITM/keyfiles, password xxxxxxxx.
>
> Any ideas?
>
> Regards,
>
> Gregory R. Mendes
> Tivoli Architect/Tools Specialist
> Mendes, Inc.
> Tivoli Monitoring 6.2.3 Certified
> 770-317-8593
>
>
> _______________________________________________
> TME10 mailing list
> [email protected]
> Unsubscribe:[email protected]
>
>
>
>
> --
> "Sometimes I think that's the only right thing to do:
> To dream. to live in the world of dreams.
> But it doesn't last forever--wakefulness always comes to take me back..."
>
>
> _______________________________________________ TME10 mailing list
> [email protected] Unsubscribe:[email protected]
>
> _______________________________________________
> TME10 mailing list
> [email protected]
> Unsubscribe:[email protected]
>
>

_______________________________________________
TME10 mailing list
[email protected]
Unsubscribe:[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.