RE: SSL Certificates and cimtrust
Venkateswara R Puvvada <[email protected]>
| Newsgroups | gmane.network.open-pegasus.general |
|---|---|
| Message-ID | <OFA808B937.56198C20-ON6525788E.002E4B29-6525788E.00304899@in.ibm.com> |
Hi Souvik, Pegasus does not support explicit modification of TrustStorePath property (absolute path of certificate) of PG_SSLCertifcate instance. I am not aware of any other solution. -Venkat From: <[email protected]> To: Venkateswara R Puvvada/India/IBM@IBMIN Cc: <[email protected]> Date: 12/05/2011 11:56 Subject: RE: SSL Certificates and cimtrust Thanks for replying, Venkat. My intent is to add it through cimtrust in a developement system, but deploy the whole Pegasus Folder in different system ( add defining necesaary env vars to run cimserver). Here I found, PG_SSLCertificate contains the absolute path in its property. It stops me from putting Pegasus folder in different location in different system. Is there any way out? Thanks Souvik From: Venkateswara R Puvvada [mailto:[email protected]] Sent: Thursday, May 12, 2011 11:47 AM To: Souvik Roy (WT01 - Manufacturing & Hi Tech) Cc: [email protected] Subject: Re: SSL Certificates and cimtrust Hi Souvik, There is no way that certificates can be installed without using the cimtrust command or using its interface (PG_SSLCertificate.addCertificate()). There is 1-1 correspondence between the actual certificate and PG_SSLCertifcate instance. Without corresponding PG_SSLCertifcate instance to the certificate, the authentication would fail. Venkat From: <[email protected]> To: <[email protected]> Date: 11/05/2011 09:57 Subject: SSL Certificates and cimtrust Hi, we want to verify a CIM Client through SSL Certificates by adding the Client Certificate using cimtrust in the CIMOM. We found that after adding though cimtrust for root user, a certificate entry is created in the sslTrustStore folder and a SSl Certificate instances are created in the repository/root#PG_Internal/instances/. In those instances, Certificate path CIM Property is assigned to the absolute path of the related certificate residing in the sslTrustStore. So the problem is, if we want to create an installer ( other modules along with CIMOM) , Installer need to put the Pegasus folder, set environment variables and start CIMOM and additionally run cimtrust to add the certificate in the repository. Is there any way to get rid of running the cimtrust in the installing systems? In that case, we will provide CIMOM folder along with repository and the sslTrustStore with the certificate, set the environment variables and start cimserver only. Thanks and regards, Souvik Roy Wipro Technologies Block - DM, Sector -V Salt Lake. Kolkata- 700091. India VOIP: 8584750 Direct: +91 33 30954750 Only when the last tree has died and the last river been poisoned and the last fish been caught will we realise we cannot eat money Please do not print this email unless it is absolutely necessary. The information contained in this electronic message and any attachments to this message are intended for the exclusive use of the addressee(s) and may contain proprietary, confidential or privileged information. If you are not the intended recipient, you should not disseminate, distribute or copy this e-mail. Please notify the sender immediately and destroy all copies of this message and any attachments. WARNING: Computer viruses can be transmitted via email. The recipient should check this email and any attachments for the presence of viruses. The company accepts no liability for any damage caused by any virus transmitted by this email. www.wipro.com Please do not print this email unless it is absolutely necessary. The information contained in this electronic message and any attachments to this message are intended for the exclusive use of the addressee(s) and may contain proprietary, confidential or privileged information. If you are not the intended recipient, you should not disseminate, distribute or copy this e-mail. Please notify the sender immediately and destroy all copies of this message and any attachments. WARNING: Computer viruses can be transmitted via email. The recipient should check this email and any attachments for the presence of viruses. The company accepts no liability for any damage caused by any virus transmitted by this email. www.wipro.com