Thank you for your trace of an SSL session. In my spare time I've been
   trying to get Telnet SSL working (I'm not an real Admin, but I play one on
   TV). Now I know what it should look like, or at least yours got farther
   than mine. I think I still have OS/400 side setup to do. Telnet SSL is
   enabled (both mode) but I don't think the system certificate is set up.
   ------ Original Message ------
   Received: 01:35 PM EDT, 04/22/2010
   From: James Rich <james@xxxxxxxxxxx>
   To: tn5250 <LINUX5250@xxxxxxxxxxxx>
   Subject: [LINUX5250] SSL with v6r1
     Hi everyone,
     Last night I configured a new v6r1 machine to use SSL. I configured a
     2048 bit key. Today x5250 fails to connect using SSL about 50% of the
     time. A tracefile shows that the certificate was successfully verified.
     However, soon after validating the certificate it appears that lib5250
     simply drops the connection. The reason it appears this was is because
     the trace file is very short. Here it is in its entirety:
     tn5250_ssl_stream_init() entered.
     SSL Method = SSLv23_client_method()
     tn5250_ssl_stream_init() success.
     tn5250_ssl_stream_connect() entered.
     Connected with SSL
     Using AES128-SHA cipher with a 128 bit secret key
     SSL Certificate issued by: (I cut this stuff out from the trace)
     SSL Certificate successfully verified!
     SSL must be Non-Blocking
     tn5250_ssl_stream_connect() success.
     tn5250_dbuffer_clear_table() entered.
     tn5250_char_map_new: map = "37"
     Macro: fname=/home/james/.tn5250macros
     I'll try and do some debugging on this later, but I wanted to check if
     anyone has had a similiar problem with v6r1 or not before I spent too
     much
     time on this. This problem occurs whether I'm on the local LAN or
     outside
     the firewall, so it doesn't appear to be related to network
     configuration
     issues. The really strange part is that it fails like this about half
     the
     time. Non-SSL connections always work perfectly. Ideas?
     James Rich
     if you want to understand why that is, there are many good books on
     the design of operating systems. please pass them along to redmond
     when you're done reading them :)
     - Paul Davis on ardour-dev
     --
     This is the Linux 5250 Development Project (LINUX5250) mailing list
     To post a message email: LINUX5250@xxxxxxxxxxxx
     To subscribe, unsubscribe, or change list options,
     visit: 
http://lists.midrange.com/mailman/listinfo/linux5250
     or email: LINUX5250-request@xxxxxxxxxxxx
     Before posting, please take a moment to review the archives
     at 
http://archive.midrange.com/linux5250.
As an Amazon Associate we earn from qualifying purchases.