+

Search Tips   |   Advanced Search

(dist)

Errors configuring SSL encrypted access for security

We might have errors returned when we are trying to configure SSL for encrypted access. Some of the common errors you might encounter and suggestions on how to fix the problems are described.

What kind of error are you seeing?

If we do not see a problem that resembles yours, or if the information provided does not solve the problem, see Troubleshooting help from IBM for further assistance.


"The Java Cryptographic Extension (JCE) files were not found." error when launching iKeyman

We might receive the following error when you attempt to start the iKeyman tool:

When you click OK, the iKeyman tool closes. To resolve this problem:


"Unable to verify MAC." error when the wrong keystore password is used

We might receive the following error when the keystore password is not being used correctly.

Change the Password field that references this keystore using the correct password. The default password is WebAS. Never use this password in a production environment.


"SSL handshake failure" error when no trusted certificate is found

We might receive the following error when you attempt to add the signer to the local truststore:

The signer might need to be added to the local truststore C:/WASX_c0602.31/AppServer/profiles/Dmgr09/etc/trust.p12 located in the SSL configuration alias DefaultSSLSettings. The truststore is loaded from the SSL configuration file.

The extended error message from the SSL handshake exception is:

This error indicates that the signer certificate from the specified target host and port has not been located in the specified truststore, the SSL settings, and the SSL configuration file. If this occurs in a client process, there are several things that we can do:

If this issue occurs in a server process, then complete one of the following procedures:

As default, Websphere Application Server uses the key.p12 and trust.p12 files for any communication between Websphere Application Servers (for example between nodeagent and appserver or vice versa). If WAS is looking for a certificate in some file other than these, then it is possible that the application establishes the secure socket layer (SSL) configuration by using system properties, established with the System.setProperty() method. That is, SSL configurations are managed for each of the processes, and we have had to maintain individual settings for each SSL configuration in the topology.

Prior to WAS v6.1, the WAS management processes allowed the individually-managed SSL configurations which were set by system properties. Your pre-Version 6.1 system properties settings were processed successfully.

With WAS v6.1, central management of SSL configuration occurs. Applications that use SSL connections based on values set for system properties instead of using the centrally managed default dynamic SSL configuration can experience handshake failures. Nodeagent to appserver communications is being governed by the default dynamic SSL configuration in WAS v6.1 and not through the system properties you set. You may need to adjust the application to use the centrally managed SSL configuration of WAS v6.1.


The certificate alias cannot be found in the keystore

We might receive the following error when the certificate alias is not found in the referenced keystore:

This error indicates that the certificate alias that was specified cannot be found in the referenced keystore. Either change the certificate alias or make sure that alias exists in the specified keystore.


Related concepts

  • Troubleshooting help from IBM