ADSM-L

Re: [ADSM-L] Antwort: ADSM-L Digest - 21 Mar 2016 to 22 Mar 2016 (#2016-56)

2016-03-23 04:48:02
Subject: Re: [ADSM-L] Antwort: ADSM-L Digest - 21 Mar 2016 to 22 Mar 2016 (#2016-56)
From: Bjoern Rackoll <backup.rackoll AT RRZ.UNI-HAMBURG DOT DE>
To: ADSM-L AT VM.MARIST DOT EDU
Date: Wed, 23 Mar 2016 09:46:21 +0100
Hi Markus,

I missed a bit that you try only client to server at the moment. This is
pretty straightforward. Here's a snippet from the dsmserv.opt of our
7.1.4 server:

TCPPort 1500
SSLTCPPORT 1502
TCPADMINPort 1501
SSLTCPADMINPort 1503
SSLTLS12 YES
ADMINONCLIENTPORT       NO

The dsm.sys for the corresponding client has:

  TCPPort            1502
  TCPAdminport       1503
  SSL                Yes

Besides, you just have to import the cert256.arm into the client's
keyring and you're ready to go.

Some of these settings are specific to our setup. If you don't use
'ADMINONCLIENTPORT NO', you don't need a 'TCPAdminport' setting on the
client.

And yes, I know that there is a bug in the TLS1.2 implementation, so the
'SSLTLS12 YES' setting should not be used in production environments at
the moment until IBM gets the GSKit error fixed. (We use it just in our
test environment.)

Regards,

    Bjoern


> Thanks David, Bjoern for the great hints!
> 
> We are testing the self-signed certificates created by the server instance,
> so at this stage, no third-party certificate is involved, using the dsmadmc
> native commandline (no hub-server, no oc, no server-to-server, all down to
> absolute basics. Using gskit and following the instructions, it works just
> fine with the 128bit certificate cert.arm, but will not connect with the
> cert256.arm. Test with TSM Server 6.3.3 on SUN shows the same behaviour. Am
> I maybe just missing some obvious settings on the TSM Server side?
> 
> Kind regards,
> Markus
> 


-- 
Björn Rackoll
Universität Hamburg
Regionales Rechenzentrum
Zentrale Dienste
Schlüterstr. 70
20146 Hamburg
Tel.: +49 (0)40 42838 - 63 11
Fax: +49 (0)40 42838 - 62 70
Mobil: +49 (0)172 427 0301
E-Mail: backup AT mailman.rrz.uni-hamburg DOT de

<Prev in Thread] Current Thread [Next in Thread>