Topic
2 replies Latest Post - ‏2013-02-14T14:01:25Z by Shishir
SystemAdmin
SystemAdmin
45 Posts
ACCEPTED ANSWER

Pinned topic SSL handshake error on connecting to DMs

‏2013-02-07T15:01:25Z |
Hi,

Just started evaluating the WAS Perf Tuning tool and it looks promising so far. Unfortunately our Live/pre-Live WAS environments mandate MASSL and I'm not sure if the tool can handle this. I can connect to development environments with no issues, as these cells don't require a MASSL connection.

I speculatively tried exporting the private/public key from one of the pre-Live cells, and inserted it into the 'cacerts' keystore on the machine that has the WAS Perf Tool installed, unfortunately I'm still getting a handshake error.

So my queries are is:

1) Has anybody else got a working connection with a cell that needs a MASSL connection
2) If so, how to you configure the tool to use a specific keystore

thanks in advance,

Paul.
Updated on 2013-02-14T14:01:25Z at 2013-02-14T14:01:25Z by Shishir
  • SystemAdmin
    SystemAdmin
    45 Posts
    ACCEPTED ANSWER

    Re: SSL handshake error on connecting to DMs

    ‏2013-02-12T11:43:24Z  in response to SystemAdmin
    Hi,

    In case anyone else in interested, after some faffing around I managed to find a solution.

    The app launches as an Eclipse plugin, and this plugin contains a configurable file called PerfTuningToolkit.ini. For me, it was installed in:

    C:\Documents and Settings\<%USER>\<%USER>\applications\eclipse\plugins\com.ibm.esupport.tool.perftool.win_2.2.0.20120510

    I was able to configure this ini file to specify JVM SSL arguments:

    -Djavax.net.ssl.trustStore=C:/Program Files/Java/jre7/lib/security/trust.p12
    -Djavax.net.ssl.trustStorePassword=*****
    -Djavax.net.ssl.keyStore=C:/Program Files/Java/jre7/lib/security/key.p12
    -Djavax.net.ssl.keyStorePassword=*****
    -Djavax.net.ssl.trustStoreType=pkcs12
    -Djavax.net.ssl.keyStoreType=pkcs12

    I then extracted the relevant certificates from the cell and imported into the local keyfiles.

    This allowed me to connect to a MASSLd cell.

    regards,

    Paul.
    • Shishir
      Shishir
      28 Posts
      ACCEPTED ANSWER

      Re: SSL handshake error on connecting to DMs

      ‏2013-02-14T14:01:25Z  in response to SystemAdmin
      Hi Paul,

      Thanks for sharing the solution with the group.

      Regards
      Shishir