Solved

Websphere SSL - Sharing Public Key

Posted on 2008-10-14
4
734 Views
Last Modified: 2013-12-11
Hi,

I am in  urgent need of a solution. Request your help.

I am using JSCH API to FTP documents to a third party site.  I am able to connect to their site by supplying credentials but they have told us that they would not accept credentials but only Public key.

From the websphere console, I went to SSL Configuration tab, and under 'Manage End Points, from the outbound node, I configured to use the default self-signed certificate for the cell.

I am assuming that I should be sharing the 'serverCertificate.arm' file under etc folder to this third-party.


My question is: Will this setting enable my application to connect to the third-party server without me writing Custom SSLFactory?

Thanks




0
Comment
Question by:pattabi23in
  • 3
4 Comments
 
LVL 41

Accepted Solution

by:
HonorGod earned 500 total points
ID: 22721358
It depends.

From your description, it sounds like you have an application that executes on
your application server that initiates the connection to the third part site.  Is that correct?

If so, then, you need to extract the public portion of the certificate being used, and provide that to the third party.  Here is a page from the 6.1 documentation that discusses certificate management:

http://publib.boulder.ibm.com/infocenter/wasinfo/v6r1/index.jsp?topic=/com.ibm.websphere.base.doc/info/aes/ae/csec_sslcertmanadmin.html

On the other hand, if the request for an SSL connection comes from the third part site, then the "public" key that you need to share with the third party site should be that of your web server, not your application server.

Hopefully, this make sense to you.
0
 

Author Comment

by:pattabi23in
ID: 22721683
Thank you for the response. Yes, my application code executing on my App server is initiating the connection.
So my understanding from your response is that once I share the public portion of the key, Websphere (network layer?) will take care of handshake without any SSL specific changes in my code. Another application within our company is using SSL api to create SSLSocket factory and SSLContext - attached code snippet). I guess this is not required if I have this configuration setup through Admin console. Right?


Thanks  

   


code-snippet.txt
0
 
LVL 41

Expert Comment

by:HonorGod
ID: 22724891
Q: ... once I share the public portion of the key, Websphere
     will take care of handshake without any SSL specific changes in my code.
     Is this correct?

A: Yes

Q: Do we need to use an SSL API to do this?
A: I don't believe so, but I guess it depends upon how your code
    opens the connect to the destination.  That is an interesting question.
    I know that should an SSL connection from a remote application (e.g.,
    a browser) be established to the web server, the connection from the
    web server (i.e., the WebSphere plugin portion of the web server)
    doesn't have to use an SSL connection to connect to the application
    server (but it can).  Once the connection is established between the
    plugin and the application server, the WebContainer will route the
    request to the specific application in question, and that application
    does not know, nor should it care whether or not the data was
    sent over an SSL, or standard HTTP session.
0
 
LVL 41

Expert Comment

by:HonorGod
ID: 22724930
Thanks for the grade & points!

Good luck & have a great day
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

So you need a certificate so you can offer SSL encryption.  But which one should you get?  There are so many choices out there! Here is a generic overview of the main types of SSL certificates sold by the majority of commercial Certification Auth…
SSL stands for “Secure Sockets Layer” and an SSL certificate is a critical component to keeping your website safe, secured, and compliant. Any ecommerce website must have an SSL certificate to ensure the safe handling of sensitive information like…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now