Friday, August 3, 2012

IBM HTTP Server - Setting up SSL using self-signed certificates

****WARNING - THIS IS SUITABLE FOR A NON-PRODUCTION ENVIRONMENT ONLY ***

You really should avoid using self-signed certificates in a production environment, bearing in mind that they typically expire within a year, and that they have not been signed by a certificate authority.

In addition, bear in mind that, by default, IHS only supports 1024-bit certificates UNLESS you choose to download/apply the unrestricted JCE policy files, as described in this Technote: -


Problem(Abstract)

The error "The specified database has been corrupted" is received when importing a pkcs12 file generated by openssl, into a jks file within ikeyman.

Symptom

If ikeyman throws "The specified database has been corrupted" error during import, chances are the pkcs12 file uses an encryption method that is not available in the default JCE policy files provided by the Java used by ikeyman.

Having accepted that this is for a non-production environment, and that you're happy with self-signed certificates, here's a quick crib sheet: -

Create the SSL keystore

$ mkdir /opt/IBM/HTTPServer/ssl
$ /opt/IBM/HTTPServer/java/jre/bin/java com.ibm.gsk.ikeyman.ikeycmd -keydb -create -db /opt/IBM/HTTPServer/ssl/key.kdb -pw Passw0rd -type cms -stash

Create the self-signed certificate ( default expiration is 12 months; I could have extended this had I chosen )

$ /opt/IBM/HTTPServer/java/jre/bin/java com.ibm.gsk.ikeyman.ikeycmd -cert -create -db /opt/IBM/HTTPServer/ssl/key.kdb -pw Passw0rd -size 1024 -dn "CN=ic301.uk.ibm.com,O=ibm" -label "ic301.uk.ibm.com" -default_cert yes

List the certificate(s) in the keystore

$ /opt/IBM/HTTPServer/bin/gsk7cmd -cert -list -db /opt/IBM/HTTPServer/ssl/key.kdb -pw Passw0rd

Certificates in database /opt/IBM/HTTPServer/ssl/key.kdb:
   ic301.uk.ibm.com
List the certificate(s) in the keystore showing more detail, including default/trusted

$ /opt/IBM/HTTPServer/bin/gsk7capicmd -cert -list -db /opt/IBM/HTTPServer/ssl/key.kdb -pw Passw0rd

/opt/IBM/HTTPServer/gsk7/bin/gsk7capicmd: error while loading shared libraries: libstdc++.so.5: cannot open shared object file: No such file or directory

Ooops - missing library :-)

$ yum install libstdc++.so.5

Loaded plugins: product-id, refresh-packagekit, rhnplugin, security, subscription-manager
Updating certificate-based repositories.
Unable to read consumer identity
Setting up Install Process
Resolving Dependencies
--> Running transaction check
---> Package compat-libstdc++-33.i686 0:3.2.3-69.el6 will be installed
--> Finished Dependency Resolution

Dependencies Resolved

============================================================================================================================================================================================================
 Package                                               Arch                                   Version                                          Repository                                              Size
============================================================================================================================================================================================================
Installing:
 compat-libstdc++-33                                   i686                                   3.2.3-69.el6                                     rhel-x86_64-server-6                                   189 k

Transaction Summary
============================================================================================================================================================================================================
Install       1 Package(s)

Total download size: 189 k
Installed size: 0 
Is this ok [y/N]: y
Downloading Packages:
compat-libstdc++-33-3.2.3-69.el6.i686.rpm                                                                                                                                            | 189 kB     00:01   
Running rpm_check_debug
Running Transaction Test
Transaction Test Succeeded
Running Transaction
  Installing : compat-libstdc++-33-3.2.3-69.el6.i686                                                                                                                                                    1/1
Installed products updated.
  Verifying  : compat-libstdc++-33-3.2.3-69.el6.i686                                                                                                                                                    1/1

Installed:
  compat-libstdc++-33.i686 0:3.2.3-69.el6                                                                                                                                                                 

Complete!
Try again

$ /opt/IBM/HTTPServer/bin/gsk7capicmd -cert -list -db /opt/IBM/HTTPServer/ssl/key.kdb -pw Passw0rd

Certificates found:
* default, - has private key, ! trusted
*-! ic301.uk.ibm.com


The job, she is a good 'un !!

*UPDATE 10 January 2013*

Note that the above point re 1024 bit certificates is relevant to IHS 7 and previous versions. IHS 8 natively supports 2048 bit certificates. Additionally, in IHS 8, the GSK command has been renamed to gskcapicmd.

IBM Connections 3 - The Missing Jython Scripts ? More ….

Following on from my earlier post - IBM Connections 3 - The Missing Jython Scripts ? - here's some more examples, now that my IC301 cluster is installed: -

$ /opt/IBM/WebSphere/AppServer/profiles/Dmgr01/bin/wsadmin.sh -lang jython -f /tmp/Wizards/Wizards/was/jython/listMember.py 

WASX7209I: Connected to process "dmgr" on node ic301 using SOAP connector;  The type of process is: DeploymentManager
Cluster1_server1(cells/ic301/clusters/Cluster1|cluster.xml#ClusterMember_1344004211970)
Cluster2_server1(cells/ic301/clusters/Cluster2|cluster.xml#ClusterMember_1344004492286)
InfraCluster_server1(cells/ic301/clusters/InfraCluster|cluster.xml#ClusterMember_1344003822736)

$ /opt/IBM/WebSphere/AppServer/profiles/Dmgr01/bin/wsadmin.sh -lang jython -f /tmp/Wizards/Wizards/was/jython/fullSyncNodes.py 

WASX7209I: Connected to process "dmgr" on node ic301 using SOAP connector;  The type of process is: DeploymentManager

I'll keep digging and see what the other scripts actually do: -

deleteOldServer.py
folderConfig.py
restartCluster.py
stopCluster.py
variableProc.py     

and how to use them.

Increasing the size of a partition using Red Hat Enterprise Linux 6.3

This follows on from an earlier post ( written in 2010 about RHEL 5.5 )

I'd originally created a 30 GB VM using the 64-bit version of RHEL 6.3, and was using it to install IBM Connections 3.0.1.1 CR2.

Sadly I ran out of disk space during the final hurdle.

Thankfully, VMware Fusion 4.1.3 ( on Mac OS X) allows me to grow the virtual disk on the fly ( from 30 GB to 50 GB ).

However, I had to remind myself how to tell Linux that the disk had grown.

This is what I had to start with: -

$ df -kmh

Filesystem            Size  Used Avail Use% Mounted on
/dev/mapper/vg_rhel6-lv_root
                       26G  8.8G   16G  37% /
tmpfs                 937M     0  937M   0% /dev/shm
/dev/sda1             485M   76M  384M  17% /boot


$ pvdisplay 

  --- Physical volume ---
  PV Name               /dev/sda2
  VG Name               vg_rhel6
  PV Size               29.51 GiB / not usable 3.00 MiB
  Allocatable           yes (but full)
  PE Size               4.00 MiB
  Total PE              7554
  Free PE               0
  Allocated PE          7554
  PV UUID               ErZzgp-aefq-eHjk-njzR-Aoq1-mUGV-olNd76

$ vgdisplay 

  --- Volume group ---
  VG Name               vg_rhel6
  System ID             
  Format                lvm2
  Metadata Areas        1
  Metadata Sequence No  3
  VG Access             read/write
  VG Status             resizable
  MAX LV                0
  Cur LV                2
  Open LV               2
  Max PV                0
  Cur PV                1
  Act PV                1
  VG Size               29.51 GiB
  PE Size               4.00 MiB
  Total PE              7554
  Alloc PE / Size       7554 / 29.51 GiB
  Free  PE / Size       0 / 0   
  VG UUID               lqlIZU-UDiA-gz5A-Xqxn-TFL7-REo3-s0lDzm

$ lvdisplay 

  --- Logical volume ---
  LV Path                /dev/vg_rhel6/lv_root
  LV Name                lv_root
  VG Name                vg_rhel6
  LV UUID                23aVS2-OAA6-B9yL-UjFf-0fhz-ycJm-vrK3r2
  LV Write Access        read/write
  LV Creation host, time , 
  LV Status              available
  # open                 1
  LV Size                25.57 GiB
  Current LE             6546
  Segments               1
  Allocation             inherit
  Read ahead sectors     auto
  - currently set to     256
  Block device           253:0
   
  --- Logical volume ---
  LV Path                /dev/vg_rhel6/lv_swap
  LV Name                lv_swap
  VG Name                vg_rhel6
  LV UUID                eX02pG-wj73-Ydjx-0vmn-Q8b3-7m9f-kZZmWi
  LV Write Access        read/write
  LV Creation host, time , 
  LV Status              available
  # open                 1
  LV Size                3.94 GiB
  Current LE             1008
  Segments               1
  Allocation             inherit
  Read ahead sectors     auto
  - currently set to     256
  Block device           253:1


This was easier than I'd expected - although my earlier blog post definitely helped: -

Create a new disk partition ( /dev/sda3 )

$ fdisk /dev/sda

Reboot to take effect

$ reboot 

Create a new physical volume on the newly created partition

$ pvcreate /dev/sda3

Extend the volume group

$ vgextend vg_rhel6 /dev/sda3

Extend the logical volume

$ lvextend /dev/mapper/vg_rhel6-lv_root /dev/sda3 

Resize the file system

$ resize2fs -p /dev/mapper/vg_rhel6-lv_root 

Check the space

$ df -kmh

Filesystem            Size  Used Avail Use% Mounted on
/dev/mapper/vg_rhel6-lv_root
                       45G   21G   22G  49% /

tmpfs                 3.9G     0  3.9G   0% /dev/shm
/dev/sda1             485M   76M  384M  17% /boot

To close the loop, here are the physical volume, volume group and logical volume statistics post the change: -

$ pvdisplay

  --- Physical volume ---
  PV Name               /dev/sda2
  VG Name               vg_rhel6
  PV Size               29.51 GiB / not usable 3.00 MiB
  Allocatable           yes (but full)
  PE Size               4.00 MiB
  Total PE              7554
  Free PE               0
  Allocated PE          7554
  PV UUID               ErZzgp-aefq-eHjk-njzR-Aoq1-mUGV-olNd76
   
  --- Physical volume ---
  PV Name               /dev/sda3
  VG Name               vg_rhel6
  PV Size               20.00 GiB / not usable 3.34 MiB
  Allocatable           yes (but full)
  PE Size               4.00 MiB
  Total PE              5119
  Free PE               0
  Allocated PE          5119
  PV UUID               ZhJrDi-tIPA-bzUe-vLJv-ifhf-UDWb-KT46Jo


$ vgdisplay 

  --- Volume group ---
  VG Name               vg_rhel6
  System ID             
  Format                lvm2
  Metadata Areas        2
  Metadata Sequence No  5
  VG Access             read/write
  VG Status             resizable
  MAX LV                0
  Cur LV                2
  Open LV               2
  Max PV                0
  Cur PV                2
  Act PV                2
  VG Size               49.50 GiB
  PE Size               4.00 MiB
  Total PE              12673
  Alloc PE / Size       12673 / 49.50 GiB
  Free  PE / Size       0 / 0   
  VG UUID               lqlIZU-UDiA-gz5A-Xqxn-TFL7-REo3-s0lDzm


$ lvdisplay

  --- Logical volume ---
  LV Path                /dev/vg_rhel6/lv_root
  LV Name                lv_root
  VG Name                vg_rhel6
  LV UUID                23aVS2-OAA6-B9yL-UjFf-0fhz-ycJm-vrK3r2
  LV Write Access        read/write
  LV Creation host, time , 
  LV Status              available
  # open                 1
  LV Size                45.57 GiB
  Current LE             11665
  Segments               2
  Allocation             inherit
  Read ahead sectors     auto
  - currently set to     256
  Block device           253:0
   
  --- Logical volume ---
  LV Path                /dev/vg_rhel6/lv_swap
  LV Name                lv_swap
  VG Name                vg_rhel6
  LV UUID                eX02pG-wj73-Ydjx-0vmn-Q8b3-7m9f-kZZmWi
  LV Write Access        read/write
  LV Creation host, time , 
  LV Status              available
  # open                 1
  LV Size                3.94 GiB
  Current LE             1008
  Segments               1
  Allocation             inherit
  Read ahead sectors     auto
  - currently set to     256
  Block device           253:1

IBM Connections 3 - Manually populating the Profiles database - who needs wizards anyway ?

With apologies to JRR Tolkien and JK Rowling

Having previously unpacked the Connections Wizards TAR file ( IBM_Connection301_Wzd_zLinux_CZVR1ML.tar ), I wanted to quickly set up the IBM Tivoli Directory Integrator (ITDI) Assembly Line needed to populate the Profiles database, without running the Wizard.

The main reason for this is that there's always a time when you can't run a GUI, especially if your client only provides you with a SSH terminal session.

I'd already installed ITDI 7.0.0.5 as mentioned previously, into /opt/IBM/TDI/V7.0, so the rest was relatively easy: -

Create the tdisol directory by copying it from the unTAR'd Wizard

$ cd /opt/IBM/TDI/V7.0/
$ mkdir tdisol_BLUEPAGES
$ cd tdisol_BLUEPAGES/
$ cp -R /tmp/Wizards/Wizards/TDIPopulation/TDISOL/linux .

Backup and update the profile_tdi.properties file

$ cd linux
$ cp profiles_tdi.properties profiles_tdi.properties.original
$ vi profiles_tdi.properties 

with the following changes: -

source_ldap_user_login=uid=user87272h,c=gb,ou=bluepages,o=ibm.com
{protect}-source_ldap_user_password=Passw0rd
source_ldap_search_base=o=ibm.com
source_ldap_search_filter=&(uid=*)(objectclass=inetOrgPerson))

dbrepos_jdbc_url=jdbc:db2://localhost:60000/peopledb
{protect}-dbrepos_password=Passw0rd


Note that I'm using IBM's internal BluePages corporate directory as my LDAP, rather than installing a local copy of Domino, Tivoli Directory Server, Active Directory etc.

Also note that the two passwords are marked for encoding via the {protect} attribute, as described in a previous post here. Therefore, next time I check the profiles_tdi.properties file, I should find: -

{protect}-source_ldap_user_password={encr}89ae788e9f88bbc8877a7729e99ac9d990ea
{protect}-dbrepos_password={encr}88ea998ef88bb277ac98eef877bb7724928e8988ae

PS Alex Lang has written an excellent article on using BluePages with WebSphere Portal 7 here.

Create and populate the collect.dns file

$ cd /opt/IBM/TDI/V7.0/tdisol_BLUEPAGES/linux
$ vi collect.dns

uid=user87272h,c=gb,ou=bluepages,o=ibm.com

Populate the Profiles database

$ cd /opt/IBM/TDI/V7.0/tdisol_BLUEPAGES/linux
$ ./populate_from_dn_file.sh 

CTGDKD024I Remote API successfully started on port:1099, bound to:'SessionFactory'. SSL and Client Authentication are enabled.
Platform: 'Generic'
CLFRN0027I: After iteration, success records is 1, duplicate records 0, failure records is 0, last successful entry is uid=user87272h,c=gb,ou=bluepages,o=ibm.com

And, bang, the job is done :-)

With thanks to the IC301 Wiki article - Manually populating the Profiles database - for inspiration.

IBM Connections 3 - The Missing Jython Scripts ?

I found this when I was poking about in the Wizards that are provided with IBM Connections 3 ( as packaged up in IBM_Connection301_Wzd_zLinux_CZVR1ML.tar ).

I'd previously mentioned this when creating the DB2 databases manually.

Looking at the directory structure that's contained with the TAR file: -

drwxr-xr-x 11 root root 4096 Mar 30  2011 connections.s390.sql
drwxr-xr-x 11 root root 4096 Mar 30  2011 connections.sql
drwxr-xr-x  2 root root 4096 Aug  2 16:23 DBWizard
-rwxr--r--  1 root root 2272 Mar 30  2011 dbWizard25.sh
-rwxr--r--  1 root root 2272 Mar 30  2011 dbWizard30.sh
drwxr-xr-x  2 root root 4096 Aug  2 16:23 depcheck
drwxr-xr-x  5 root root 4096 Mar 30  2011 jvm
drwxr-xr-x  5 root root 4096 Aug  3 11:09 lib
-rwxr--r--  1 root root 2097 Mar 30  2011 populationWizard.sh
drwxr-xr-x  2 root root 4096 Aug  2 16:23 samples
drwxr-xr-x  2 root root 4096 Aug  2 16:23 script
drwxr-xr-x  3 root root 4096 Aug  2 16:23 TDIPopulation
drwxr-xr-x  3 root root 4096 Mar 30  2011 was


I was especially interested in the was subdirectory, which contains: -

was/:
total 12
drwxr-xr-x  3 root root 4096 Mar 30  2011 .
drwxr-xr-x 12 root root 4096 Mar 30  2011 ..
drwxr-xr-x  2 root root 4096 Aug  2 16:23 jython

was/jython:
total 48
drwxr-xr-x 2 root root 4096 Aug  2 16:23 .
drwxr-xr-x 3 root root 4096 Mar 30  2011 ..
-rwxr--r-- 1 root root 1162 Mar 30  2011 deleteOldServer.py
-rwxr--r-- 1 root root 1513 Mar 30  2011 dmcellname.py
-rwxr--r-- 1 root root 6461 Mar 30  2011 folderConfig.py
-rwxr--r-- 1 root root 1767 Mar 30  2011 fullSyncNodes.py
-rwxr--r-- 1 root root  953 Mar 30  2011 listMember.py
-rwxr--r-- 1 root root 2570 Mar 30  2011 restartCluster.py
-rwxr--r-- 1 root root 2206 Mar 30  2011 stopCluster.py
-rwxr--r-- 1 root root 4876 Mar 30  2011 variableProc.py


I had a quick play with some of them: -

$ /opt/IBM/WebSphere/AppServer/profiles/Dmgr01/bin/wsadmin.sh -lang jython -f was/jython/dmcellname.py 

WASX7209I: Connected to process "dmgr" on node ic301 using SOAP connector;  The type of process is: DeploymentManager
[[ic301]]


$ /opt/IBM/WebSphere/AppServer/profiles/Dmgr01/bin/wsadmin.sh -lang jython -f was/jython/listMember.py 

WASX7209I: Connected to process "dmgr" on node ic301 using SOAP connector;  The type of process is: DeploymentManager

( I don't yet have a node federated into my cell .... )

I'll play around with this once I've completed my IC3011 installation, and add a bit more info ....

Update strategy for IBM Connections 3.0.1.1

Am posting this as I know I'll need it quite soon


This document describes the recommended strategy and steps for applying maintenance updates to IBM Connections 3.0.1.1.


<snip>
Abstract

This document lists the fixed APARs included in IBM Connections 3.0.1.1 CR2 cumulative fix.

Content

Cumulative Refreshes (CRs) consists of a set of cumulative fixes for each of IBM Connections applications. For additional information on CRs, including instructions on how to download and install, please review the Update strategy for IBM Connections 3.0.1.1 document.
CR2 is composed of this set of 14 cumulative fixes, which update the whole application. Each fix is identified by an APAR number, also known as its "CR Fix ID". CR2 fixes are listed in this table
</snip>

Thursday, August 2, 2012

IBM Connections - Preparing the DB2 Databases Manually ( of course )

Am writing this down, because I *know* I'll need it again at some point, but will update for Connections 4 when it ships in 2H 2012.

Preparing the Wizard

$ cd /tmp/
$ mkdir Wizards
$ cd Wizards/
$ tar xvf ~/IBM_Connection301_Wzd_zLinux_CZVR1ML.tar 

Creating the databases

$ cd /tmp/Wizards/Wizards/connections.sql/

Activites

$ db2 -td@ -vf activities/db2/createDb.sql 
$ db2 -td@ -vf activities/db2/appGrants.sql 

Blogs

$ db2 -td@ -vf blogs/db2/createDb.sql 
$ db2 -td@ -vf blogs/db2/appGrants.sql 

Communities

$ db2 -td@ -vf communities/db2/createDb.sql 
$ db2 -td@ -vf communities/db2/appGrants.sql 

Bookmarks ( Dogear )

$ db2 -td@ -vf dogear/db2/createDb.sql 
$ db2 -td@ -vf dogear/db2/appGrants.sql 

Files

$ db2 -td@ -vf files/db2/createDb.sql 
$ db2 -td@ -vf files/db2/appGrants.sql 

Forums

$ db2 -td@ -vf forum/db2/createDb.sql 
$ db2 -td@ -vf forum/db2/appGrants.sql 

Homepage

$ db2 -tvf homepage/db2/createDb.sql 
$ db2 -tvf homepage/db2/appGrants.sql 
$ db2 -tvf homepage/db2/initData.sql 
$ db2 -tvf homepage/db2/reorg.sql 
$ db2 -tvf homepage/db2/updateStats.sql 

Profiles

$ db2 -tvf profiles/db2/createDb.sql 
$ db2 -tvf profiles/db2/appGrants.sql 

Wikis

$ db2 -td@ -vf wikis/db2/createDb.sql 
$ db2 -td@ -vf wikis/db2/appGrants.sql 

Thanks to the Wiki for the assist