Thank you for your trace of an SSL session. In my spare time I've been
trying to get Telnet SSL working (I'm not an real Admin, but I play one on
TV). Now I know what it should look like, or at least yours got farther
than mine. I think I still have OS/400 side setup to do. Telnet SSL is
enabled (both mode) but I don't think the system certificate is set up.
------ Original Message ------
Received: 01:35 PM EDT, 04/22/2010
From: James Rich <james@xxxxxxxxxxx>
To: tn5250 <LINUX5250@xxxxxxxxxxxx>
Subject: [LINUX5250] SSL with v6r1
Hi everyone,
Last night I configured a new v6r1 machine to use SSL. I configured a
2048 bit key. Today x5250 fails to connect using SSL about 50% of the
time. A tracefile shows that the certificate was successfully verified.
However, soon after validating the certificate it appears that lib5250
simply drops the connection. The reason it appears this was is because
the trace file is very short. Here it is in its entirety:
tn5250_ssl_stream_init() entered.
SSL Method = SSLv23_client_method()
tn5250_ssl_stream_init() success.
tn5250_ssl_stream_connect() entered.
Connected with SSL
Using AES128-SHA cipher with a 128 bit secret key
SSL Certificate issued by: (I cut this stuff out from the trace)
SSL Certificate successfully verified!
SSL must be Non-Blocking
tn5250_ssl_stream_connect() success.
tn5250_dbuffer_clear_table() entered.
tn5250_char_map_new: map = "37"
Macro: fname=/home/james/.tn5250macros
I'll try and do some debugging on this later, but I wanted to check if
anyone has had a similiar problem with v6r1 or not before I spent too
much
time on this. This problem occurs whether I'm on the local LAN or
outside
the firewall, so it doesn't appear to be related to network
configuration
issues. The really strange part is that it fails like this about half
the
time. Non-SSL connections always work perfectly. Ideas?
James Rich
if you want to understand why that is, there are many good books on
the design of operating systems. please pass them along to redmond
when you're done reading them :)
- Paul Davis on ardour-dev
--
This is the Linux 5250 Development Project (LINUX5250) mailing list
To post a message email: LINUX5250@xxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit:
http://lists.midrange.com/mailman/listinfo/linux5250
or email: LINUX5250-request@xxxxxxxxxxxx
Before posting, please take a moment to review the archives
at
http://archive.midrange.com/linux5250.
As an Amazon Associate we earn from qualifying purchases.