Dave,

The SSLSERV code has not changed from 4.4. to 5.1.  In lue of the port
number question, have you tried starting and stopping your TCPIP server and
then letting that re-ipl SSLSERV (or doing it manually)?  Sometimes simple
things are overlooked.

Recently had fun with SSLSERV myself, and I use PCOMM all the time here.



-----Original Message-----
From: VM/ESA and z/VM Discussions
To: [email protected]
Sent: 10/14/05 3:47 PM
Subject: Re: VM SSLSERV and PCOMM

To make this point even clearer, when the z/VM 5.1 system was installed,
the SSLSERV (Linux kernel and all) was simply DDR-ed into a CMS file,
moved over to the 5.1 system, and DDR-ed back to DASD. The IBM provided
SSL code inside the SSLSERV itself is the code from 4.4. Might this be a
problem? I didn't see where that code had changed in going from 4.4 to
5.1.

DJ

Alan Altmark wrote:
> On Friday, 10/14/2005 at 01:04 EST, Dave Jones
<[EMAIL PROTECTED]> 
> wrote:
> 
>>The client put a network sniffer of the incoming connection and they
are
>>able to see my incoming SSL connection (which makes it all the way to
>>the SSLSERV SVM) and then a response back that looks like a CP error
>>message:
>>HCPCMD001E    UNKNOWN CP COMMAND: R...
>>
>>This is SSLSERV running on a 5.1 image, btw.
> 
> 
> That looks suspiciously like you didn't change the port number in your

> PCOMM config to point to the encrypted port, so the client handshake
is 
> going to the unencrypted port.  (What the heck, activate the SSL
trace. If 
> you don't see any activity, the connection didn't go through the SSL 
> server.)
> 
> Alan Altmark
> z/VM Development
> IBM Endicott



The contents of this e-mail are intended for the named addressee only. It
contains information that may be confidential. Unless you are the named
addressee or an authorized designee, you may not copy or use it, or disclose
it to anyone else. If you received it in error please notify us immediately
and then destroy it. 

Reply via email to