Yes, the TLS client profile already exists and is being referred to by both V8 and V9 QM. The TLS profile contains both validation and identification credentials. Please find the certificate object and TLS details configured in the QM Connections in the attached document.
I have noticed below error in DataPower.
Original Message:
Sent: Fri May 30, 2025 02:24 AM
From: Ajitabh Sharma
Subject: DataPower MQ to MQ V9+ Objects migration
DataPower uses object name regardless of it's storage type. Did you create and attached a TLS client profile with MQ QM in DataPower? What errors do you see in DataPower?
------------------------------
Ajitabh Sharma
Original Message:
Sent: Sun May 25, 2025 01:32 AM
From: Sampelly Vikram Rao
Subject: DataPower MQ to MQ V9+ Objects migration
Hi All,
We're currently migrating MQ objects from DataPower V8 to V9 and facing an issue with establishing the MQ Queue Manager connection.
In V8, we used a user object, but in V9 this has been deprecated and now requires specifying a certificate label for mutual TLS.
Here's what we've done:
We uploaded the client certificate (dpmq.ibm.com.cer) into the DataPower cert store.
Mapped it to a Crypto Certificate object named DP_MQ_TLS.
In the MQ Queue Manager object, we set the SSL Certificate Label to DP_MQ_TLS.
However, the Queue Manager remains down, and the MQ logs show:
AMQ9640: Certificate was not sent by the remote application.
We suspect that the label provided might not be correctly referencing the private key, especially since the private key is stored in the HSM.
Question:
What exactly should be provided as the SSL Certificate Label in this case?
Should it be the Certificate name(dpmq.ibm.com.cer) or Crypto Certificate object name (DP_MQ_TLS) or the HSM key label?
Appreciate any guidance or examples on how to properly reference HSM-backed certs in this scenario.
------------------------------
Sampelly Vikram Rao
Original Message:
Sent: Mon May 19, 2025 11:50 PM
From: Mahesh Varma Buddaraju
Subject: DataPower MQ to MQ V9+ Objects migration
Hi Stephan Jacob,
we have raised a case with IBM but no solution has been provided by the so far, we are on DP Version 10.6.0.4, we will plan to upgrade to 10.6.0.5 and test it.
I will keep you posted how it goes Stephan, Thanks for your time.
Regards,
Mahesh
------------------------------
Mahesh Varma Buddaraju
Original Message:
Sent: Fri May 16, 2025 02:57 AM
From: Stephen Jacob
Subject: DataPower MQ to MQ V9+ Objects migration
Hi Mahesh,
Yes we have been experienced the same issue MQRC 2142 over various firmware versions. We are working with IBM via case. no fix/cause from IBM as yet.
I suggest that you also raise a IBM case .. more examples from more locations will like help then get to root cause/solution quicker I imagine.
As you say it occurs with MQ9+ but does not occur MQV8 client MQ objects.
10.6.0.5 is out and addresses various MQ issues :
DT424936 MQ v9+ handler might continuously consume messages when its admin-state is disabled.
DT426022 MQ v9+ handler cannot route messages to the specified queue in ObjectName of MQOD.
DT433392 IBM MQ v9+ queue manager might stop to retry connections when network conditions are unstable
DT435251 DataPower might restart when cleaning up MQ connections
We experienced the second issue in 10.6.0.4 : DT426022.
regards,
Stephen
------------------------------
Stephen Jacob
Senior Analyst Engineer
NAB
VIC
Original Message:
Sent: Mon May 05, 2025 08:54 PM
From: Mahesh Varma Buddaraju
Subject: DataPower MQ to MQ V9+ Objects migration
Hi Team,
we are trying to configure MQV9+ Migration in Datapower , after the migration we are facing issue with below error logs in Splunk
2024-11-07T14:20:54+11:00,10.17.197.178,err,0x8d200055,[mq][error] source-idg-mq(*******FSH_V9): trans(102643136) gtid(aadd9dd9672c3ddd****): Failed to put message to (A001F0.**.**.**_COMMON03_***.REPLY.UAT), reason: 2142.
2025-03-17T18:31:06+11:00,10.17.197.179,err,0x80e00616,[mpgw][error] mpgw(MediationRouter01): trans(74663)[10.17.197.217] gtid(8e43863e67d7cfa6010ff333): Network Error (Connection timed out) on Back interface (URL: idgmq://ESB2_MQQMGroup01/?RequestQueue=A0028E.**.***.***.REQUEST.EUAT;ReplyQueue=GN.**.DP.***.CV.REPLY.EUAT1;SetReplyTo=true;ParseHeaders=off) when processing the server response
2025-03-17T18:31:06+11:00,10.104.176.63,err,E*B2_EU*T1,[0x80e00648][mq][error] mpgw(MediationRouter01): trans(48305346)[10.17.197.217] gtid(8e43863e67d7cfa6010ff333): internal error, IBM MQ Reason Code = 901, IBM MQ URL = idgmq://ESB2_MQQMGroup01/?RequestQueue=A0028E.**.***.GESB.REQUEST.EUAT;ReplyQueue=GN.QA.DP.ESB.CV.REPLY.EUAT1;SetReplyTo=true;ParseHeaders=off
We are on 10.6.0.4, we thought the issues will be fixed when we migration from 10.6.0.3
when we revert back the changes to older MQ ( Deprecated object ) it is working fine.
anyone faced similar issue ?
Regards,
Mahesh
------------------------------
Sri Rama Mahesh Varma Buddaraju
------------------------------