Dear Jozsef
>>>>> Also came up with a process where we can identify the certificate used by a specific TLS connection using the TRCCNN command and analysing the output using Wireshark. <<<<<
I'm interested in learning how to do this. Please help post the information when you have free time.
Thanks.
------------------------------
Chance favors only the prepared mind.
-- Louis Pasteur
------------------------------
Satid S.
------------------------------
Original Message:
Sent: Tue September 19, 2023 01:41 AM
From: Jozsef Torok
Subject: IBM i DCM - Last Use Timestamp for each certificate
Hi Satid,
I like the idea, and have voted.
By coincidence I have very recently been doing quite a bit of certificate work that led to running an audit of TLS connections that includes a running count of TLS connections. This is via the SST Advanced Analysis command TLSCONFIG, and setting the required options in the QAUDLVL system value.
Also came up with a process where we can identify the certificate used by a specific TLS connection using the TRCCNN command and analysing the output using Wireshark. This was more a case of being curious that after a certificate change that the subsequent TLS connections were using the correct (new) certificate.
If this is something you may be interested in I can send more details later.
Regards,
Jozsef.