TEC604523: MQMonitor Error: 2393 MQRC_SSL_INITIALIZATION_ERROR with SSL CIpherSpec

Document created by DavidLewis Employee on May 26, 2016Last modified by J.J. Lovett on May 26, 2016
Version 2Show Document
  • View in full screen mode

Document ID:  TEC604523

Last Modified Date:  1/13/2014
Authored By: DavidLewis

  • Products
    • CA Application Performance Management
    • CA Introscope
  • Releases
    • CA Application Performance Management:Release:9.1 SP2
    • CA Application Performance Management:Release:9.1.0
    • CA Application Performance Management:Release:9.1.1
    • CA Application Performance Management:Release:CA APM 9.5
  • Components
    • PPK FOR IBM WEBSPHERE MQ
    • APM POWER PACKS

 

Description:Depending on which CipherSpec you use for SSL connection to your MQ Queue Manager from the MQMonitor agent, you may observe the following errors in the MQMonitor log:2393 MQRC_SSL_INITIALIZATION_ERRORCiphers we have seen generating this error include:

  • TLS_RSA_WITH_AES_128_CBC_SHA
  • FIPS_WITH_3DES_EDE_CBC_SHA.

cipherspec is specified in MQMonitor.properties:

# <Queue Manager>@<Host>.channel.ssl.cipherspec
# SSL cipherspec of the given Queue Manager to be monitored
# Default=none, if it is not set
#
QM1@hostname.channel.ssl.cipherspec = XXXXX_XXXXX

Solution:

This problem is governed by the type of JVM used.
We recommend using the latest IBM JVM to run the MQMonitor, as it provides support for CipherSpecs that may be unavailable with an Oracle JVM.
It was noted that TRIPLE_DES_SHA_US works with both IBM and Oracle JVMs.

 

Search the Entire CA APM Knowledge Base

 

search-kb.jpg

Attachments

    Outcomes