× The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.



On Thu, Apr 7, 2022 at 8:22 AM Jack Woehr via MIDRANGE-L <
midrange-l@xxxxxxxxxxxxxxxxxx> wrote:

On Thu, Apr 7, 2022 at 7:12 AM Brad Stone <bvstone@xxxxxxxxx> wrote:

You got it right, Greg. With most TCPIP using SSL/TLS you need to import
the CA(s) used by the server system so your IBM i "trusts" the
certificate
(to be more specific, it makes your system trust the issuers of the
certificate... ie.. the Certificate Authority).


To be more specific:

Your garden-variety website presents a certificate which points back to a
well-known Certificate Authority, usually through a chain.
That is, their cert is signed by A.COM whose cert is verified by B.COM
whose cert is verified by the top-level authority C.COM


No, they're signed by Authorities, not ".coms" That sort of obfuscates
things more.



The reason us IBM i folks spend so much time installing certs via DCIM is
that our in-house certs and those of our EDI partners are often
*self-signed*, hence, *invalid* on the face of things.


Having dealt with thousands of customers on this, I can say this isn't true
either. It's just that IBM doesn't pre-load every CA out there.

Helping customers import CAs I've probably done 1 self-signed to 1000 well
known CAs. Most were from well known sites like Google and Microsoft and
GoDaddy.

I put together docs to help them import CAs (and extract them from a
website or using openSSL), but that didn't help most (over their head). So
then when I found out I could bypass the "trust" I added that in and my
life has 50% more free time. :)

Brad
www.bvstools.com

As an Amazon Associate we earn from qualifying purchases.

This thread ...

Follow-Ups:
Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.