Client authentication breaks Relay

(imported topic written by GwyndafDavies)

Hello,

I have an environment which I’m enabling client authentication for a number of relays. I’ve been doing some general testing and I can’t get clients to talk to an authenticating relay.

The moment I make a relay an authenticating one via the client setting "
_BESRelay_Comm_Authenticating=1"
all the clients drop off and switch to their secondary. The client log file clearly shows that it attempts to connect but I get an error:
Registration backing off from SSL, attempting in clear text

Also, if I try to check relay diagnostics after enabling an authenticating relay (http://:52311/rd) I get a 403 error and the page doesn’t load.

Any ideas on where I can troubleshoot further? Any environment configurations I need to double check?

I’m on version 9.1.1117

Cheers,

Gwyn

(imported comment written by ErikEvenson)

I have a client with a similar issue here.

_BESRelay_Comm_Authenticating=1

_BESRelay_Diagnostics_Enable=0

RegisterOnce: GetURL failed - HTTP 403 Error (Forbidden) - 'http://:52311/cgi-bin/bfenterprise/clientregister.exe

(imported comment written by GwyndafDavies)

Hi Erik,

This particular issue seems to be with 9.1x (not sure if it effects more than one version however I experienced it wit 9.1.1117) that will hopefully be fixed for the next release
. In the meantime, you can try a manual key exchange as a short term fix:

http://www-01.ibm.com/support/knowledgecenter/SS63NW_9.1.0/com.ibm.tivoli.tem.doc_9.1/Platform/Console/ManualKeyExchange.html%23Manualkeyexchange?cp=SS63NW_9.1.0&lang=en

(imported comment written by ErikEvenson)

Hello Gwyndaf,

Thanks for the reply. Do you know if there is an APAR on this?

Thanks again!

(imported comment written by JonLandis)

We are also on 9.1.1117. I see this issue too. It seems that this also breaks relay affiliation. The clients I have upgraded to 9.1.1117 have all reported to either their failover server or the main server. Doing ‘relay select’ does not get them to their local relay even when I confirmed it is available.

3 posts were split to a new topic: Advice and documentation on using authenticating relays