Hey HG
We actually have a VeriSign cert our Systems group loaded into our DummyServerTrustFile (I know I know, not my choice to use this - lack of standards in this area) and our java/jre/lib/security/cace
We kept getting SSLHandShakeFailed: expired cert.
After going round and round and doing some research this is where we've come:
1) Updating webservicesclient.xml (& associated ibm-webserviceclient-bnd/e
>I kept getting mixed results.(variety of SSLHandShake exceptions (key not found / expired cert)
2) Testing a local standalone webservice client (using IBM's handy test JSP testClient.jsp) with no changes to webserviceclient AND a new CERT file in root C:\
> I am now getting a WebServiceTimeout.
(This tells me I am hitting the WS service
and causing it to think at least - no exception.)
3) I read on some tech forum to remove expired certs (point #2's test)
4) I asked our Systems group to remove expired certs from both Server Trust AND cacerts.
> and we are going to try to WS call as-is (no other configuration changes - This test is pending.)
QUESTION:
Do you have any suggestions to follow or things to consider as we try to conquer this SSL handshake error?
Thanks
- - - - - - -
John 14:6
Main Topics
Browse All Topics





by: HonorGodPosted on 2009-09-03 at 05:57:52ID: 25250144
When you say that you "updated the ServerTrustFile with a new certificate", what tool, and process was used to do this?
com/infoce nter/wasin fo/v5r1// i ndex.jsp?t opic=/com. ibm.websph ere.base.d oc/info/ae s/ae/ tsec_ mngcert.ht ml
Did you use the iKeyman utility?
Is the certificate from a Certificate Authority (CA), or is it self-signed?
Here's the documentation in the Information Center about "Managing Digital Certificates"
http://publib.boulder.ibm.