Forums >> IBM Power Systems >> (QGPL) IBM i

Jump to:




polarbear101

V6R1 after cumulative PTF SSL not working

Posted:

V6R1 after cumulative PTF SSL not working

Hi *all


After installing cumulative PTF on V6R1 our SSL Client (Mochasoft) is not working anymore.
We don't have a software contract, IBM gives no support, even payed !
Options in STRSST are not working (Security Bulletin CVE-2014-3566).
It is also not possible to access the DCM via port 2001.
SSL-Telnet is up and running according to netstat *cnn.

It seems that SSL V3 is disabled, but a proper error message is not available.
Also downloaded the latest "Java-Client iAccess", same result: NO SSL connection.

Thank you for any help.

 

Regards




Latest Posts:

GreenTools For G Suite (G4G) v12.00 Released With Base OAuth 2.0 Functionality GreenTools For G Suite (G4G) v12.00 Released With Base OAuth 2.0 Functionality
Posted by July 28, 2019
BVSTools >> BVSTools Announcements >> GreenTools for G Suite (Google Apps) (G4G) Specific Announcements
BVSTools Small Price Increase in 2020 BVSTools Small Price Increase in 2020
Posted by July 26, 2019
BVSTools >> BVSTools Announcements
GreenTools for Vertex Cloud (VTXCLOUD) Now Available GreenTools for Vertex Cloud (VTXCLOUD) Now Available
Posted by July 22, 2019
BVSTools >> BVSTools Announcements >> GreenTools for Vertex Cloud (VTXCLOUD) Specific Announcements
GreenTools for Google Apps (G4G) - Drive Addon Successfully Verified by Google GreenTools for Google Apps (G4G) - Drive Addon Successfully Verified by Google
Posted by July 22, 2019
BVSTools >> BVSTools Announcements >> GreenTools for G Suite (Google Apps) (G4G) Specific Announcements
Why I Cancelled my DynDNS Service and How I Replaced It with an IBM i Application Why I Cancelled my DynDNS Service and How I Replaced It with an IBM i Application
Posted by July 17, 2019
IBM Power Systems >> (QGPL) IBM i
Green Tools for G Suite (G4G) Product Updates (Licensing, Functionality, Base Product) Green Tools for G Suite (G4G) Product Updates (Licensing, Functionality, Base Product)
Posted by July 13, 2019
BVSTools >> BVSTools Announcements >> GreenTools for G Suite (Google Apps) (G4G) Specific Announcements
Reading JSON Data from Standard Input With YAJL and RPG Reading JSON Data from Standard Input With YAJL and RPG
Posted by July 12, 2019
Programming >> Proof of Concept (POC)
MAILTOOL Updated to Allow Use of IBM Global Security Kit (GSKIT) for SSL/TLS Communications MAILTOOL Updated to Allow Use of IBM Global Security Kit (GSKIT) for SSL/TLS Communications
Posted by June 19, 2019
BVSTools >> BVSTools Announcements >> eMail Tool (MAILTOOL) Specific Announcements
GETURI v10.00 Released Supporting IBM Global Security Kit (GSKIT) and Server Name Indication (SNI) GETURI v10.00 Released Supporting IBM Global Security Kit (GSKIT) and Server Name Indication (SNI)
Posted by June 11, 2019
BVSTools >> BVSTools Announcements >> Get URI (GETURI) Specific Announcements
BVSTools Now Offers Vertex Cloud Interface BVSTools Now Offers Vertex Cloud Interface
Posted by April 15, 2019
BVSTools >> BVSTools Announcements
Token Has an Invalid Signature Error for Office 365 Email Token Has an Invalid Signature Error for Office 365 Email
Posted by March 22, 2019
BVSTools >> BVSTools Software Discussion >> GreenTools for Microsoft Apps (G4MS) Specific Discussion
Resending Emails that have Errored Out with Updated Router or Authentication Information Resending Emails that have Errored Out with Updated Router or Authentication Information
Posted by March 1, 2019
BVSTools >> BVSTools Software Discussion >> Email Tools (MAILTOOL) Specific Discussion
BVSTools Offers Toolset to Work With HubSpot OAuth 2.0 APIs On Your IBM i BVSTools Offers Toolset to Work With HubSpot OAuth 2.0 APIs On Your IBM i
Posted by January 27, 2019
BVSTools >> BVSTools Announcements
G4MSDRV Currently Not Supported G4MSDRV Currently Not Supported
Posted by January 17, 2019
BVSTools >> BVSTools Announcements >> GreenTools for Microsoft Apps (G4MS) Specific Announcements
Removing Trailing Carriage Returns and/or Line Feeds from a String with RPG Removing Trailing Carriage Returns and/or Line Feeds from a String with RPG
Posted by December 26, 2018
Programming >> RPG Programming
bvstone

RE: V6R1 after cumulative PTF SSL not working

Posted:

RE: V6R1 after cumulative PTF SSL not working

Try getting to DCM using this link:

http://youribmiaddress:2001/QIBM/ICSS/Cert/Admin/qycucm1.ndm/main0

Replace "youribmiaddress" with the IP address of your IBM i.  Also, make sure the *ADMIN instance is running.

I've seen many systems where the IBM i tasks page just won't come up, but this link works.

As for Mochasoft, do they provide support?  Perhaps it needs an update as well?


Last edited 11/20/2015 at 07:18:00



polarbear101

RE: RE: V6R1 after cumulative PTF SSL not working

Posted:

RE: RE: V6R1 after cumulative PTF SSL not working

Hi , thank you for your answer, sorry for the delay but there was no notification.

Your trick works, the dcm is displayed but it not helps much. Can't see any certificates.

Tried much, but nothing helped yet. 

Mochasoft gave support, but even the latest version not works.

I make my tests now local with the Java-client "IBM i access client solutions", so client and server is from IBM.
The client works fine with the public-server "pub1.de".


Last edited 11/27/2015 at 09:50:46



polarbear101

RE: RE: RE: V6R1 after cumulative PTF SSL not working

Posted:

RE: RE: RE: V6R1 after cumulative PTF SSL not working

T H A N K   Y O U  !!!

After some testing i gained access to to DCM with the link you provided.

Renewed the 512 bytes certificate and put it to all services.
With 1024 bytes certificates the ssl-client didn't work.

After enabling SSLV3 and SSL Renegotiation without RFC 5746 to 'ALL' all works fine as before.
For details check Security Bulletin (CVE-2014-3566). Current link (IBM links often changes) :
http://www-01.ibm.com/support/docview.wss?uid=swg21687173
​http://www-01.ibm.com/support/docview.wss?uid=nas8N1020451

Things i learned:
- won't touch an IBM System i with an outdated release, even when outdated only 2 months !
- won't touch an IBM System i without hardware AND software maintanence !
If something happens, IBM gives you just NO SUPPORT. In the case above costs for a "renewal" of the contract where over $ 7k !

Have a nice weekend

Regards


Last edited 11/28/2015 at 03:22:15




Reply




Copyright 1983-2019 BVSTools
GreenBoard(v3) Powered by the eRPG SDK, MAILTOOL Plus!, GreenTools for Google Apps, jQuery, jQuery UI, BlockUI, CKEditor and running on the IBM i (AKA AS/400, iSeries, System i).