Re: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-27 Thread Ganesh Murthy
users@qpid.apache.org > Sent: Monday, June 27, 2016 10:02:49 AM > Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener > > You are right. Nevertheless, working with security is never easy as there are > so many options to configure and a lot of points to be careful at

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-27 Thread Adel Boutros
ever have found it without your help! :) > > > > Do you think it could be worth submitting a Jira issue for clearer error > > messages? > > > > Regards, > > Adel > > > > > From: adelbout...@live.com > > > To: users@qpid.apache.org

Re: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-27 Thread Ganesh Murthy
2 intermediate certificates.) Thanks. - Original Message - > From: "Adel Boutros" <adelbout...@live.com> > To: users@qpid.apache.org > Sent: Friday, June 24, 2016 12:19:24 PM > Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener > &

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Adel Boutros
; Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener > Date: Fri, 24 Jun 2016 18:14:11 +0200 > > Solved it!! > > The order of the certificates in the chain file ca-chain.cert.pem is > important. I inverted the order of the certificates by putting the

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Adel Boutros
tie...@live.com > To: users@qpid.apache.org > Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener > Date: Fri, 24 Jun 2016 16:09:00 + > > Following your lines : > > SUCCESS > --> qdstat -c > --ssl-trustfile=PATH_TO_CERT_DIR/ganesh/ca-cer

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Paolo Patierno
Linkedin : paolopatierno Blog : DevExperience > From: adelbout...@live.com > To: users@qpid.apache.org > Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener > Date: Fri, 24 Jun 2016 18:03:43 +0200 > > Yes, everything is ran on the same machine. I had configured a singl

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Adel Boutros
tierno > Blog : DevExperience > > > From: adelbout...@live.com > > To: users@qpid.apache.org > > Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener > > Date: Fri, 24 Jun 2016 17:56:56 +0200 > > > > > > > > Nope, I > > am us

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Paolo Patierno
Senior Software Engineer (IoT) @ Red Hat Microsoft MVP on Windows Embedded & IoTMicrosoft Azure Advisor Twitter : @ppatierno Linkedin : paolopatierno Blog : DevExperience > From: adelbout...@live.com > To: users@qpid.apache.org > Subject: RE: [Qpid-Dispatch] SSL/SASL configuration

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Adel Boutros
ey are corrupt and that the qdstat is unable to load them and is thus failing before sending anything? Regards, Adel > From: ppatie...@live.com > To: users@qpid.apache.org > Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener > Date: Fri, 24 Jun 2016 15:41:51 + > >

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Paolo Patierno
rosoft MVP on Windows Embedded & IoTMicrosoft Azure Advisor Twitter : @ppatierno Linkedin : paolopatierno Blog : DevExperience > From: adelbout...@live.com > To: users@qpid.apache.org > Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener > Date: Fri, 24 Jun 2016

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Adel Boutros
Paolo, There is no traffic in the case of the failure. So I cannot provide a pncap file :( > From: adelbout...@live.com > To: users@qpid.apache.org > Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener > Date: Fri, 24 Jun 2016 17:35:56 +0200 > > It seem

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Adel Boutros
It seems like attachments are not really working. You can check the images here: http://imgur.com/a/WlssO Adel From: adelbout...@live.com To: users@qpid.apache.org Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener Date: Fri, 24 Jun 2016 17:31:45 +0200 Wireshark Pictures

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Paolo Patierno
edin : paolopatierno Blog : DevExperience From: adelbout...@live.com To: users@qpid.apache.org Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener Date: Fri, 24 Jun 2016 17:31:45 +0200 Wireshark Pictures attached. Adel From: adelbout...@live.com To: users@qpid.apache.org Subject

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Adel Boutros
Success === Failure > From: adelbout...@live.com > To: users@qpid.apache.org > Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener > Date: Fri, 24 Jun 2016 17:26:44 +0200 > > I fixed the CN part (Thanks Paol

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Adel Boutros
in the failure case (Wireshark display filter: "tcp.port == 10398") Regards, Adel > Date: Fri, 24 Jun 2016 11:17:18 -0400 > From: gmur...@redhat.com > To: users@qpid.apache.org > Subject: Re: [Qpid-Dispatch] SSL/SASL configuration on a listener > > Good catch Paolo, I should note h

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Paolo Patierno
From: gmur...@redhat.com > To: users@qpid.apache.org > Subject: Re: [Qpid-Dispatch] SSL/SASL configuration on a listener > > Good catch Paolo, I should note here that qdstat and qdmanage commands do > *not* do hostname verification by default. I submitted a pull request for > ht

Re: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Ganesh Murthy
Patierno" <ppatie...@live.com> > To: users@qpid.apache.org > Sent: Friday, June 24, 2016 11:09:56 AM > Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener > > Hi Adel, > > is this just a typo or the real CN you are using ? > > /CN=CN=12

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Paolo Patierno
rosoft MVP on Windows Embedded & IoTMicrosoft Azure Advisor Twitter : @ppatierno Linkedin : paolopatierno Blog : DevExperience > From: ppatie...@live.com > To: users@qpid.apache.org > Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener > Date: Fri, 24 Jun 2016 15:03:44 +0

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Paolo Patierno
tter : @ppatierno Linkedin : paolopatierno Blog : DevExperience From: adelbout...@live.com To: users@qpid.apache.org Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener Date: Fri, 24 Jun 2016 16:48:54 +0200 Thank you Paolo. @Ganesh, I was able to successfully connect using your

Re: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Ganesh Murthy
log : DevExperience > > > From: adelbout...@live.com > > To: users@qpid.apache.org > > Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener > > Date: Fri, 24 Jun 2016 13:03:29 +0200 > > > > Hello Ganesh, > > > > Thank you for your

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-24 Thread Adel Boutros
? Is is just the intermediate certificate? Or the root certificate? Or a combination of both? Regards, Adel > Date: Thu, 23 Jun 2016 14:07:20 -0400 > From: gmur...@redhat.com > To: users@qpid.apache.org > Subject: Re: [Qpid-Dispatch] SSL/SASL configuration on a listener > > Hi

Re: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-23 Thread Ganesh Murthy
t;Ganesh Murthy" <gmur...@redhat.com> > To: users@qpid.apache.org > Sent: Thursday, June 23, 2016 10:17:06 AM > Subject: Re: [Qpid-Dispatch] SSL/SASL configuration on a listener > > I also want to add that there is a file called > qpid-dispatch/tests/ssl_certs/gencerts.sh

Re: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-23 Thread Ganesh Murthy
these self signed certs and also cover various SASL scenarios. Thanks. - Original Message - > From: "Ganesh Murthy" <gmur...@redhat.com> > To: users@qpid.apache.org > Sent: Thursday, June 23, 2016 10:05:08 AM > Subject: Re: [Qpid-Dispatch] SSL/SASL configu

Re: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-23 Thread Ganesh Murthy
can make sure that your root CA is never compromised. Thanks. - Original Message - > From: "Adel Boutros" <adelbout...@live.com> > To: users@qpid.apache.org > Sent: Thursday, June 23, 2016 9:56:02 AM > Subject: RE: [Qpid-Dispatch] SSL/SASL configuration

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-23 Thread Adel Boutros
and test again. Thanks for the helpful explanation! Regards, Adel > From: ppatie...@live.com > To: users@qpid.apache.org > Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener > Date: Thu, 23 Jun 2016 13:31:56 + > > Hi Adel, > > I'm a bit confuse

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-23 Thread Paolo Patierno
Microsoft MVP on Windows Embedded & IoTMicrosoft Azure Advisor Twitter : @ppatierno Linkedin : paolopatierno Blog : DevExperience > From: adelbout...@live.com > To: users@qpid.apache.org > Subject: RE: [Qpid-Dispatch] SSL/SASL configuration on a listener > Date: Thu, 23 Jun 201

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-23 Thread Adel Boutros
thread, steps to generate server certificate and use it in the dispatcher. I think something similar here is the easiest solution. Regards, Adel > From: ja...@scholz.cz > Date: Thu, 23 Jun 2016 14:27:11 +0200 > Subject: Re: [Qpid-Dispatch] SSL/SASL configuration on a listener &g

Re: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-23 Thread Jakub Scholz
jks contains the cert_ssl_encryption.pem and > clientKeyStore.jks contains the sasl certificate (cert_sasl.pem) which is > aliased by "client" > > Should I merge cert_sasl.pem and cert_ssl_encryption.pem in the > ssl-profile? > > Regards, > Adel > > > Date: Wed, 22 Jun 2016 1

RE: [Qpid-Dispatch] SSL/SASL configuration on a listener

2016-06-23 Thread Adel Boutros
rge cert_sasl.pem and cert_ssl_encryption.pem in the ssl-profile? Regards, Adel > Date: Wed, 22 Jun 2016 11:23:16 -0400 > From: gmur...@redhat.com > To: users@qpid.apache.org > Subject: Re: [Qpid-Dispatch] SSL/SASL configuration on a listener > > "Of course I want to use a cert