Author Topic: Spectrum Protect(TSM) expired certificate problem with database backups  (Read 252 times)

zeus1996

  • Jr. Member
  • **
  • Posts: 37
    • View Profile
Hi. certicate expired at spectrum protect (TSM) server, renewed it with this guide:
https://www.empalis.de/en/ibm-spectrum-protect-server-certificate-cert256arm-expired-troubleshooting-tips/
After that clients were able to connect to Spectrum, but Spectrum protects database (db2) backups failed.

errors:
tsmbgr log: ANS1579E GSKit function gsk_secure_soc_init failed with 406: GSK_ERROR_IO
activity log: ANR8599W The connection with S00030.tapiodmz01.fi:62300 failed due to an untrusted server certificate

so no connection in activity log with user:NODE:$$_TSMDBMGR_$$, which starts database backup

renewed also splicert files from Nodes\$$_TSMDBMGR_$$ folder

Have not found out what actual cert is backup using

thanks for answers



Justin Derrick

  • IBM Content Manager OnDemand Consultant
  • Administrator
  • Hero Member
  • *****
  • Posts: 2231
  • CMOD Guru for hire...
    • View Profile
    • Tenacious Consulting
You didn't mention if you're using a Certificate Authority (CA) or a self-signed certificate, so the answer will be a little vague...

Check DB2's key database for the Spectrum Protect server certificate -- if the SP server cert is self-signed, you'll have to add a copy to the DB2 database's key db.  If the SP server cert was signed by your organization's CA, then you need to make sure you have the full certificate chain (root + intermediate certificates) inside that key database.

-JD.
IBM CMOD Professional Services: http://TenaciousConsulting.com
Call:  +1-866-533-7742  or  eMail:  jd@justinderrick.com
IBM CMOD Wiki:  https://CMOD.wiki/
FREE IBM CMOD Education & Webinars:  https://CMOD.Training/

Interests: #AIX #Linux #Multiplatforms #DB2 #TSM #SP #Performance #Security #Audits #Customizing #Availability #HA #DR

zeus1996

  • Jr. Member
  • **
  • Posts: 37
    • View Profile
Thanks Justin, yes imported cert256.arm to nodename keybase, problem solved

jsquizz

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 576
    • View Profile
Just as an FYI - I have also seen this scenario when loading into S3/EMC, we had to add the .cer provided by the storage folks for it to work.
#CMOD #DB2 #AFP2PDF #TSM #AIX #RHEL #AWS #AZURE #GCP #EVERYTHING