Please find below our answers.

Note that we have chanage the cert name, now we are using "127.0.0.1"

On 07/24/2019 03:01 PM, Gordon Sim wrote:
On 24/07/2019 3:17 pm, Jose Alberto Fernandez Parejo wrote:
After several tests it seems that qpid-cpp is not reading nor sending
the certificate because if not env variable QPID_SSL_CERT_NAME is set
the same result it is shown.

What if ssl_cert_name is pass in the options? E.g.

 {protocol:amqp1.0,ssl_cert_name:127.0.0.1-Client}
If the ssl_cert_name is pass in the options,

# client amqp:ssl:127.0.0.1:5671  {protocol:amqp1.0,ssl_cert_name:127.0.0.1}


terminate called after throwing an instance of
'qpid::messaging::InvalidOptionString'
  what():  Invalid option string: protocol:amqp1.0


But note that if option only is set the ssl_cert_name

# client amqp:ssl:127.0.0.1:5671  {ssl_cert_name:127.0.0.1}

Now it seems that the certificate is read, this was not seen when set
the environment variable. But the connect is not for 1.0



2019-07-25 07:56:39 [Security] debug SslConnector created for 0-10
2019-07-25 07:56:39 [Security] debug ssl-cert-name = 127.0.0.1
2019-07-25 07:56:39 [System] info Connecting: 127.0.0.1:5671
2019-07-25 07:56:39 [System] debug Exception constructed: Failed: NSS
error [-8172]
(/local/users/jafparejo/Downloads/qpid-cpp-master-1.41/src/qpid/sys/ssl/SslSocket.cpp:205)
2019-07-25 07:56:39 [Security] warning Connect failed: Failed: NSS error
[-8172]
(/local/users/jafparejo/Downloads/qpid-cpp-master-1.41/src/qpid/sys/ssl/SslSocket.cpp:205)
2019-07-25 07:56:39 [Client] debug Connection  closed
2019-07-25 07:56:39 [System] debug Exception constructed: Connection  closed
2019-07-25 07:56:39 [Client] info Failed to connect to
amqp:ssl:127.0.0.1:5671: Connection  closed
Failed to connect (reconnect disabled)




What do you see for:

 certutil -L -d /tmp/db -n 127.0.0.1-Client -f /tmp/pwf

It shows the certififcate

# certutil -L -d db -n "127.0.0.1" -f pwf
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 43986 (0xabd2)
        Signature Algorithm: PKCS #1 SHA-256 With RSA Encryption
        Issuer: "CN=Certificate
Authority,OU=section,O=Company,L=City,ST=Stat           e,C=XX"

        Validity:

            Not Before: Thu Jul 25 07:45:47 2019

            Not After : Fri Jul 24 07:45:47 2020

        Subject: "CN=127.0.0.1,OU=section,O=Company,ST=State,C=XX"

        Subject Public Key Info:

            Public Key Algorithm: PKCS #1 RSA Encryption

            RSA Public Key:

                Modulus:

                    e7:8f:66:c9:74:dd:0f:a7:7a:2f:da:94:59:b3:fc:de:

                    aa:fb:71:ef:98:06:50:fb:8b:ae:69:bf:60:5b:8f:da:

                    8e:a6:b2:95:43:eb:25:18:e5:ea:53:69:2a:b4:ce:44:

                    5b:58:ec:30:b9:69:73:c6:8e:d5:1d:ea:45:08:f6:ae:

                    4b:1f:5a:af:13:fe:8a:d8:3a:56:a6:df:3f:aa:e3:fe:

                    76:ff:57:c8:43:5a:a7:b8:92:6a:19:07:c0:5e:45:b5:

                    41:57:30:34:6f:c1:a0:3d:8d:50:37:0c:61:cf:85:e2:

                    d3:bc:ee:12:30:ed:24:b0:32:3b:df:cd:6e:06:bc:3d

                Exponent: 65537 (0x10001)

        Signed Extensions:

            Name: Certificate Basic Constraints

            Data: Is not a CA.


            Name: Certificate Comment
            Comment: "OpenSSL Generated Certificate"

            Name: Certificate Subject Key ID
            Data:
                f2:e6:a0:b7:6b:0e:5a:8e:8f:7e:82:32:ad:aa:dc:47:
                c7:d2:6c:1e

            Name: Certificate Authority Key Identifier
            Issuer:
                Directory Name: "CN=Certificate
Authority,OU=section,O=Compan
                    y,L=City,ST=State,C=XX"

            Serial Number:

                00:ae:6f:1c:f4:fe:04:be:bf


    Signature Algorithm: PKCS #1 SHA-256 With RSA Encryption
    Signature:
        34:88:67:de:f0:e7:cf:1c:a9:41:2a:9d:1c:fe:b2:bb:
        34:44:9d:fa:01:82:68:e6:e6:a4:8a:af:06:be:2e:5f:
        cd:80:d7:84:0f:a0:9b:3c:2f:af:40:d3:a0:87:b3:d8:
        59:45:b5:21:67:82:1b:7b:6e:94:f5:b5:21:72:25:73:
        05:d1:cc:bb:8e:59:36:d6:8c:09:5f:89:dd:12:62:bb:
        99:bf:db:5e:9a:b1:80:2f:85:b5:38:59:f1:46:b3:b5:
        a5:f0:31:be:fb:af:af:4f:91:c4:2f:b9:f7:66:21:33:
        e2:89:c8:45:96:e3:11:a8:d6:a5:69:89:83:eb:38:66
    Fingerprint (SHA-256):

58:26:EA:64:A2:E7:10:37:D9:3B:53:E8:BC:19:0E:70:9F:BA:83:A5:56:88:1F:D4:91:2C:56:B5:86:E5:4B:67
    Fingerprint (SHA1):
        2F:C9:51:A2:FC:1A:65:E8:68:27:92:19:D2:C7:DF:5D:BD:EE:7E:F8

    Certificate Trust Flags:
        SSL Flags:
            User
        Email Flags:
            User
        Object Signing Flags:
            User



---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

.


________________________________

Este correo electrónico y, en su caso, cualquier fichero anexo al mismo, 
contiene información de carácter confidencial exclusivamente dirigida a su 
destinatario o destinatarios. Si no es vd. el destinatario indicado, queda 
notificado que la lectura, utilización, divulgación y/o copia sin autorización 
está prohibida en virtud de la legislación vigente. En el caso de haber 
recibido este correo electrónico por error, se ruega notificar inmediatamente 
esta circunstancia mediante reenvío a la dirección electrónica del remitente.
Evite imprimir este mensaje si no es estrictamente necesario.

This email and any file attached to it (when applicable) contain(s) 
confidential information that is exclusively addressed to its recipient(s). If 
you are not the indicated recipient, you are informed that reading, using, 
disseminating and/or copying it without authorisation is forbidden in 
accordance with the legislation in effect. If you have received this email by 
mistake, please immediately notify the sender of the situation by resending it 
to their email address.
Avoid printing this message if it is not absolutely necessary.

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to