dbTalk Databases Forums  

SQL Anywhere Monitor unable to create resource that will use HTTPS and FIPS

sybase.public.sqlanywhere.general sybase.public.sqlanywhere.general


Discuss SQL Anywhere Monitor unable to create resource that will use HTTPS and FIPS in the sybase.public.sqlanywhere.general forum.



Reply
 
Thread Tools Display Modes
  #1  
Old   
Rachan Terrell
 
Posts: n/a

Default SQL Anywhere Monitor unable to create resource that will use HTTPS and FIPS - 12-02-2009 , 11:18 AM






Here is our MobiLink Service Properties:



C:\Program Files\SQL Anywhere 11\Bin32\mlsrv11.exe



-c "dsn=ODBC_Connection_To_SQLAnywhereServer;UID=Mobi linkUser;PWD=MobilinkPassword"
-o "E:\Programs\WMMSDOLML\mlserver.log" -dl
-v+
-fips
-os 24M
-x https(host=11.1234.567.890;port=HostIpPort;tls_typ e=rsa;fips=y;identity=C:\Programs\tls_cert_server. crt;identity_password=IdPasswordNumbers



The MobiLink service above work and we are able to login via Sybase Central. We are able to create SQL Anywhere Server's resource by SQL Anywhere Monitor but we are not able to create MobiLink Server's resource because it could not locate the server. Any help with this would greatly appreciative.



Add Resource: Server



Host: 11.1234.567.890

Port:

Connection Type: try all of them (HTTP, HTTPs, TCP/IP, TLS)

Encryption Type: try all of them with above combinations (ECC, RSA, RSA (FIPS 140-2 certified)



Please note that the Host: 11.1234.567.890 Ip address is not real....but the one we use is. Also the dsn=ODBC_Connection_To_SQLAnywhereServer have different IP address for the database server.



Are there any thing special that we need to do using HTTPS connection.



Best regards,

Rachan Terrell

Reply With Quote
  #2  
Old   
Dan Petker [Sybase iAnywhere]
 
Posts: n/a

Default Re: SQL Anywhere Monitor unable to create resource that will useHTTPS and FIPS - 12-03-2009 , 10:01 AM






Hi Rachan,

The SQL Anywhere Monitor doesn't support monitoring FIPS-encrypted ML
servers "out of the box" since FIPS is a separately licensed component.

However, so long as you have purchased enough FIPS licenses, you may
consider the SA Monitor one of your FIPS clients and use it to monitor
FIPS-encrypted ML servers.

In order to do this, you will need to copy mlcrsafips11.dll from your ML
client install to the bin32 directory of your SQL Anywhere Monitor
install. After doing this, you should be able to monitor FIPS-encrypted
ML servers normally.

Hope this helps.

Dan Petker
iAnywhere Tools Development

Rachan Terrell wrote:
Quote:
Here is our MobiLink Service Properties:



C:\Program Files\SQL Anywhere 11\Bin32\mlsrv11.exe



-c
"dsn=ODBC_Connection_To_SQLAnywhereServer;UID=Mobi linkUser;PWD=MobilinkPassword"

-o "E:\Programs\WMMSDOLML\mlserver.log" -dl
-v+
-fips
-os 24M
-x
https(host=*11.1234.567.890*;port=HostIpPort;tls_t ype=rsa;fips=y;identity=C:\Programs\tls_cert_serve r.crt;identity_password=IdPasswordNumbers



The MobiLink service above work and we are able to login via Sybase
Central. We are able to create SQL Anywhere Server's resource by SQL
Anywhere Monitor but we are not able to create MobiLink Server's
resource because it could not locate the server. Any help with this
would greatly appreciative.



Add Resource: Server



Host: *11.1234.567.890*

Port:

Connection Type: try all of them (HTTP, HTTPs, TCP/IP, TLS)

Encryption Type: try all of them with above combinations (ECC, RSA, RSA
(FIPS 140-2 certified)



Please note that the Host: *11.1234.567.890 *Ip address is not
real....but the one we use is. Also the
*dsn=ODBC_Connection_To_SQLAnywhereServer* have different IP address for
the database server.



Are there any thing special that we need to do using HTTPS connection.



Best regards,

Rachan Terrell









Reply With Quote
  #3  
Old   
Josh Savill [Sybase]
 
Posts: n/a

Default Re: SQL Anywhere Monitor unable to create resource that will useHTTPS and FIPS - 12-03-2009 , 10:02 AM



Rachan,

Are you getting a specific error back from the SQL Anywhere Monitor?

The only thing I noticed was the port number between the MobiLink server and SQL Anywhere monitor.
On you mlsrv11 command line you specify:

-x
https(host=11.1234.567.890;port=HostIpPort;tls_typ e=rsa;fips=y;identity=C:\Programs\tls_cert_server. crt;identity_password=IdPasswordNumbers)

The port=HostIpPort must be the same port you specify when attempting to connect from the SQL
Anywhere Monitor. By default the MobiLink server listens on port 443 for HTTPS communication if you
do not specify port=

According to below:

Host: *11.1234.567.890*
Port:

you're not specifying a port number.

--
Joshua Savill
Sybase Inc. - Product Manager



Rachan Terrell wrote:

Quote:
Here is our MobiLink Service Properties:



C:\Program Files\SQL Anywhere 11\Bin32\mlsrv11.exe



-c
"dsn=ODBC_Connection_To_SQLAnywhereServer;UID=Mobi linkUser;PWD=MobilinkPassword"

-o "E:\Programs\WMMSDOLML\mlserver.log" -dl
-v+
-fips
-os 24M
-x
https(host=*11.1234.567.890*;port=HostIpPort;tls_t ype=rsa;fips=y;identity=C:\Programs\tls_cert_serve r.crt;identity_password=IdPasswordNumbers



The MobiLink service above work and we are able to login via Sybase
Central. We are able to create SQL Anywhere Server's resource by SQL
Anywhere Monitor but we are not able to create MobiLink Server's
resource because it could not locate the server. Any help with this
would greatly appreciative.



Add Resource: Server



Host: *11.1234.567.890*

Port:

Connection Type: try all of them (HTTP, HTTPs, TCP/IP, TLS)

Encryption Type: try all of them with above combinations (ECC, RSA, RSA
(FIPS 140-2 certified)



Please note that the Host: *11.1234.567.890 *Ip address is not
real....but the one we use is. Also the
*dsn=ODBC_Connection_To_SQLAnywhereServer* have different IP address for
the database server.



Are there any thing special that we need to do using HTTPS connection.



Best regards,

Rachan Terrell









Reply With Quote
  #4  
Old   
Rachan Terrell
 
Posts: n/a

Default Re: SQL Anywhere Monitor unable to create resource that will use HTTPS and FIPS - 12-03-2009 , 04:02 PM



Josh,

With Dan help we were able to set up SQL Anywhere Monitor for our MobiLink
server. Our problem were that we did not know where to put our trusted
certificates. Per Dan suggestion we used the "Other" field of the Configure
Resource wizards for the trusted certificates and it work.

Thank you very much for your help with the Port 443

Best regards,
Rachan Terrell

"Josh Savill [Sybase]" <no_spam_jsavill_no_spam (AT) sybase (DOT) com> wrote

Quote:
Rachan,

Are you getting a specific error back from the SQL Anywhere Monitor?

The only thing I noticed was the port number between the MobiLink server
and SQL Anywhere monitor. On you mlsrv11 command line you specify:

-x
https(host=11.1234.567.890;port=HostIpPort;tls_typ e=rsa;fips=y;identity=C:\Programs\tls_cert_server. crt;identity_password=IdPasswordNumbers)

The port=HostIpPort must be the same port you specify when attempting to
connect from the SQL Anywhere Monitor. By default the MobiLink server
listens on port 443 for HTTPS communication if you do not specify port=

According to below:

Host: *11.1234.567.890*
Port:

you're not specifying a port number.

--
Joshua Savill
Sybase Inc. - Product Manager



Rachan Terrell wrote:

Here is our MobiLink Service Properties:

C:\Program Files\SQL Anywhere 11\Bin32\mlsrv11.exe

-c
"dsn=ODBC_Connection_To_SQLAnywhereServer;UID=Mobi linkUser;PWD=MobilinkPassword"
-o "E:\Programs\WMMSDOLML\mlserver.log" -dl
-v+
-fips
-os 24M
-x
https(host=*11.1234.567.890*;port=HostIpPort;tls_t ype=rsa;fips=y;identity=C:\Programs\tls_cert_serve r.crt;identity_password=IdPasswordNumbers

The MobiLink service above work and we are able to login via Sybase
Central. We are able to create SQL Anywhere Server's resource by SQL
Anywhere Monitor but we are not able to create MobiLink Server's resource
because it could not locate the server. Any help with this would greatly
appreciative.

Add Resource: Server

Host: *11.1234.567.890*

Port:

Connection Type: try all of them (HTTP, HTTPs, TCP/IP, TLS)

Encryption Type: try all of them with above combinations (ECC, RSA, RSA
(FIPS 140-2 certified)

Please note that the Host: *11.1234.567.890 *Ip address is not
real....but the one we use is. Also the
*dsn=ODBC_Connection_To_SQLAnywhereServer* have different IP address for
the database server.

Are there any thing special that we need to do using HTTPS connection.

Best regards,

Rachan Terrell


Reply With Quote
Reply




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Powered by vBulletin Version 3.5.3
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.