Forums >> IBM Power Systems >> (QGPL) IBM i

Jump to:




polarbear101

V6R1 after cumulative PTF SSL not working

Posted:

V6R1 after cumulative PTF SSL not working

Hi *all


After installing cumulative PTF on V6R1 our SSL Client (Mochasoft) is not working anymore.
We don't have a software contract, IBM gives no support, even payed !
Options in STRSST are not working (Security Bulletin CVE-2014-3566).
It is also not possible to access the DCM via port 2001.
SSL-Telnet is up and running according to netstat *cnn.

It seems that SSL V3 is disabled, but a proper error message is not available.
Also downloaded the latest "Java-Client iAccess", same result: NO SSL connection.

Thank you for any help.

 

Regards




Latest Posts:

Create QRCODE in DDS Create QRCODE in DDS
Posted by September 21, 2018
Programming >> RPG Programming
Base64 Encoding a File with RPG Base64 Encoding a File with RPG
Posted by September 6, 2018
Programming >> RPG Programming
Building JSON with RPG and YAJL and Writing to Standard Output Building JSON with RPG and YAJL and Writing to Standard Output
Posted by August 31, 2018
Programming >> Proof of Concept (POC)
How to Delete Files or Empty Trash From Your Google Drive with your IBM i and RPG/ILE How to Delete Files or Empty Trash From Your Google Drive with your IBM i and RPG/ILE
Posted by July 24, 2018
BVSTools >> BVSTools Software Discussion >> GreenTools for G Suite (Google Apps) (G4G) Specific Discussion
GreenTools for G Suite (G4G) Updated to Include Delete and Empty Trash Function GreenTools for G Suite (G4G) Updated to Include Delete and Empty Trash Function
Posted by July 24, 2018
BVSTools >> BVSTools Announcements >> GreenTools for G Suite (Google Apps) (G4G) Specific Announcements
What to Do If Your License Keys Don't Work What to Do If Your License Keys Don't Work
Posted by July 18, 2018
BVSTools >> BVSTools Software Discussion
MAILTOOL Updated to Allow Failed Message on Invalid Recipient MAILTOOL Updated to Allow Failed Message on Invalid Recipient
Posted by May 20, 2018
BVSTools >> BVSTools Announcements >> eMail Tool (MAILTOOL) Specific Announcements
Non HTTPS Callbacks Removed from GreenTools for G Suite (G4G) Non HTTPS Callbacks Removed from GreenTools for G Suite (G4G)
Posted by April 15, 2018
BVSTools >> BVSTools Announcements >> GreenTools for G Suite (Google Apps) (G4G) Specific Announcements
IBM i Related Survey Available IBM i Related Survey Available
Posted by April 7, 2018
IBM Power Systems >> (QGPL) IBM i
BVSTools Releases Braintree Webhook Open Source Application - Node.js BVSTools Releases Braintree Webhook Open Source Application - Node.js
Posted by April 5, 2018
Programming >> Open Source
BVSTools Now Offering Web Services (BETA) BVSTools Now Offering Web Services (BETA)
Posted by April 3, 2018
BVSTools >> BVSTools Announcements
Creating a Reverse SSL Proxy Using RPG on the IBM i - Part 2 Creating a Reverse SSL Proxy Using RPG on the IBM i - Part 2
Posted by March 29, 2018
Programming >> Web Programming
Still on V7R1 or Earlier?  Here's Why You Should Upgrade NOW! Still on V7R1 or Earlier? Here's Why You Should Upgrade NOW!
Posted by February 21, 2018
IBM Power Systems >> (QGPL) IBM i
Converting a MMDDYY date format to YYMMDD for Sorting Using SQL Converting a MMDDYY date format to YYMMDD for Sorting Using SQL
Posted by February 16, 2018
Programming >> RPG Programming
Moving All Files from a Google Drive Folder to the Trash Using GreenTools for Google Apps (G4G) Moving All Files from a Google Drive Folder to the Trash Using GreenTools for Google Apps (G4G)
Posted by February 3, 2018
BVSTools >> BVSTools Software Discussion >> GreenTools for G Suite (Google Apps) (G4G) Specific Discussion
bvstone

RE: V6R1 after cumulative PTF SSL not working

Posted:

RE: V6R1 after cumulative PTF SSL not working

Try getting to DCM using this link:

http://youribmiaddress:2001/QIBM/ICSS/Cert/Admin/qycucm1.ndm/main0

Replace "youribmiaddress" with the IP address of your IBM i.  Also, make sure the *ADMIN instance is running.

I've seen many systems where the IBM i tasks page just won't come up, but this link works.

As for Mochasoft, do they provide support?  Perhaps it needs an update as well?


Last edited 11/20/2015 at 07:18:00



polarbear101

RE: RE: V6R1 after cumulative PTF SSL not working

Posted:

RE: RE: V6R1 after cumulative PTF SSL not working

Hi , thank you for your answer, sorry for the delay but there was no notification.

Your trick works, the dcm is displayed but it not helps much. Can't see any certificates.

Tried much, but nothing helped yet. 

Mochasoft gave support, but even the latest version not works.

I make my tests now local with the Java-client "IBM i access client solutions", so client and server is from IBM.
The client works fine with the public-server "pub1.de".


Last edited 11/27/2015 at 09:50:46



polarbear101

RE: RE: RE: V6R1 after cumulative PTF SSL not working

Posted:

RE: RE: RE: V6R1 after cumulative PTF SSL not working

T H A N K   Y O U  !!!

After some testing i gained access to to DCM with the link you provided.

Renewed the 512 bytes certificate and put it to all services.
With 1024 bytes certificates the ssl-client didn't work.

After enabling SSLV3 and SSL Renegotiation without RFC 5746 to 'ALL' all works fine as before.
For details check Security Bulletin (CVE-2014-3566). Current link (IBM links often changes) :
http://www-01.ibm.com/support/docview.wss?uid=swg21687173
​http://www-01.ibm.com/support/docview.wss?uid=nas8N1020451

Things i learned:
- won't touch an IBM System i with an outdated release, even when outdated only 2 months !
- won't touch an IBM System i without hardware AND software maintanence !
If something happens, IBM gives you just NO SUPPORT. In the case above costs for a "renewal" of the contract where over $ 7k !

Have a nice weekend

Regards


Last edited 11/28/2015 at 03:22:15




Reply




Copyright 1983-2018 BVSTools
GreenBoard(v3) Powered by the eRPG SDK, MAILTOOL Plus!, GreenTools for Google Apps, jQuery, jQuery UI, BlockUI, CKEditor and running on the IBM i (AKA AS/400, iSeries, System i).