DataPower

DataPower

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

Implicit certificates configuration in IBM Datapower

  • 1.  Implicit certificates configuration in IBM Datapower

    Posted Tue August 31, 2021 08:19 PM

    I would like to know whether is there any way in Datapower to connect remote backends without explicit use of Proxy Profile o SSL Client Profile?

    In other words, acting as web browsers where is not necessary to tell web browser which certificate(s) is(are) required to use in order to connect to a secure connection?

    I appreciate any information or link related to this and justify to managers and chiefs that use explicit of certificates are correct or not in Datapower due to a problem we are facing now.

    Regards



    #DataPower
    #Support
    #SupportMigration


  • 2.  RE: Implicit certificates configuration in IBM Datapower

    Posted Wed September 01, 2021 07:41 AM

    Hi,

    I think you always have to define the client profile but not necessarily the certificates. You can create a TLS Client profile without id or validation credentials, or in other words you don't have to explicitly specify the certificates.

    --HP



    #DataPower
    #Support
    #SupportMigration


  • 3.  RE: Implicit certificates configuration in IBM Datapower

    Posted Tue September 07, 2021 05:58 PM

    Hi:


    Do you have any IBM documentation about your response? I'll try this and thank you.


    Regards



    #DataPower
    #Support
    #SupportMigration


  • 4.  RE: Implicit certificates configuration in IBM Datapower

    Posted Wed September 08, 2021 05:20 AM

    It isn't stated explicitly but if you look at the configuration and the documentation in IBM Knowledge center you can see that id and validation credentials are optional.

    https://www.ibm.com/docs/en/datapower-gateways/10.0.1?topic=profiles-creating-tls-client-profile

    --HP



    #DataPower
    #Support
    #SupportMigration


  • 5.  RE: Implicit certificates configuration in IBM Datapower

    Posted Mon October 04, 2021 04:11 PM

    Hi

    I have developed a few tests without validation credentials and all of them work well, but I want to know deeper about how does Datapower obtain the right certicate to use during handshake? Is there a truststore inside Datapower where global CAs are located?

    Regards



    #DataPower
    #Support
    #SupportMigration


  • 6.  RE: Implicit certificates configuration in IBM Datapower

    Posted Wed October 06, 2021 06:21 AM

    Can you specify what you mean by "obtain the right certificate"? Client certificate is only used in handshake if the server is enforcing client authentication. Server certificate is validated if you want to enforce validation. Otherwise you are just doing a "normal" handshake.


    --HP



    #DataPower
    #Support
    #SupportMigration


  • 7.  RE: Implicit certificates configuration in IBM Datapower

    Posted Thu October 14, 2021 08:41 PM

    Hi again:


    Reading next link https://www.ibm.com/support/pages/public-certificates-and-datapower-gateway public CA were removed from pubcert: in Datapower. In the newest versions of Datapower were public CA are located? Or is mandatory upload all manually?


    Regards



    #DataPower
    #Support
    #SupportMigration


  • 8.  RE: Implicit certificates configuration in IBM Datapower

    Posted Thu October 14, 2021 08:46 PM

    In other words, is there a truststore in Datapower with all public Root certificates?



    #DataPower
    #Support
    #SupportMigration


  • 9.  RE: Implicit certificates configuration in IBM Datapower

    Posted Fri October 15, 2021 06:14 AM

    Hi,

    seems that the public certs have been completely moved. I am not absolutely sure about this because I have been using Docker form-factor for the past four years and I don't have any access to other types of DataPower environments. At least for Docker there aren't any public certs available in the latest V10 firmware version. Anyways, I have always uploaded the certs that I have needed. Never used the ones that IBM had supplied.


    --HP



    #DataPower
    #Support
    #SupportMigration