Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Problem Changing ikeyMan 7.0.4.14

132 views
Skip to first unread message

ste...@synerforteglobal.com

unread,
Jan 16, 2009, 10:23:54 AM1/16/09
to
I am using Ikeyman supplied with IBM HTTP Server 6.1. The problem is that the default signature algorithm is MD5WithSHA. However, I want to implement a signature algorithm of SHA1WithRSA. I tried changing this in the ikeycmd.properties and ikmuser.properties file which I passed on the command line but this doesnt seem to work as the relevant property entry doesnt appear to be picked up. The ikminit.properties is only useful for GUI and I am using the CLI. Please how can I make this change of the default signature algorithm.

Eric Covener

unread,
Jan 16, 2009, 11:36:22 AM1/16/09
to

gsk7capicmd is much faster, defaults to SHA1, and is pretty close
feature wise by 7.0.4.14. I would discourage from using these tools to
sign certificates as this feature is essentially for test purposes only.

--
Eric Covener

Eric Covener

unread,
Jan 19, 2009, 7:20:59 AM1/19/09
to

If you have access to IHS 7.0, you can use java/jre/bin/ikeycmd instead
of gsk7cmd, and it understands a new -sig_alg parameter.

Option B is to acquire any IBM Java 6 JRE, add the IBMCMSKS provider to
java.security, and use the bundled ikeycmd or your /bin/gsk7cmd with
JAVA_HOME pointing at the new JRE -- sig_alg will be accepted there as well.


--
Eric Covener

0 new messages