ASG
IBM
Zystems
Cressida
Icon
Netflexity
 
  MQSeries.net
Search  Search       Tech Exchange      Education      Certifications      Library      Info Center      SupportPacs      LinkedIn  Search  Search                                                                   FAQ  FAQ   Usergroups  Usergroups
 
Register  ::  Log in Log in to check your private messages
 
RSS Feed - WebSphere MQ Support RSS Feed - Message Broker Support

MQSeries.net Forum Index » IBM MQ Security » SSL certs with MQ that don't have Client Authentication EKU

Post new topic  Reply to topic
 SSL certs with MQ that don't have Client Authentication EKU « View previous topic :: View next topic » 
Author Message
jamesb
PostPosted: Thu Oct 30, 2025 1:49 am    Post subject: SSL certs with MQ that don't have Client Authentication EKU Reply with quote

Novice

Joined: 09 Mar 2008
Posts: 18

Hi all,
We currently use IBM MQ 9.3.0.x and use SSL to authenticate the MQ clients that attach so we have a keystore on the server side and typically a Java JKS file on the client side. When the client connects we check some element of the common name to allow it to connect. We also use it for queue manager to queue manager connectivity. Our current provider of SSL certificates (Sectigo) has contacted us to say that they are deprecating the Client Authentication EKU information from their future Sectigo SSL/TLS Certificates as they say:
"TLS certificates have been used for both the client authentication as well as server authentication, a practice that is being deprecated".

This means that mutual TLS (mTLS) won't work as I understand it. With this information no longer provided for Client Authentication purposes, including mTLS or server-to-server authentication, can anyone confirm will this still work with MQ or will we need a different provider/product?

This is detailed statement on their website is shown here:
https://www.sectigo.com/faq-client-authentication-eku-deprecation?utm_campaign=8589971-2025%20Email%20Marketing%20Summary&utm_medium=email&_hsenc=p2ANqtz--LO-lzkK8okQAJ3svD0AZHq7uGJ1RG6zKMGDV3P9X1Cyhr7gFiQZJ36sfsVfmVKtzF_QBF5llrR3HQfabHvC7IgGCXpg&_hsmi=384007955&utm_content=384007955&utm_source=hs_email

I put a ticket into IBM, but got a reply which didn't really give me a straight yes/no answer which I was hoping for! Just wondered if anyone else had experienced this and if you need to take action.

Thanks, James.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic  Reply to topic Page 1 of 1

MQSeries.net Forum Index » IBM MQ Security » SSL certs with MQ that don't have Client Authentication EKU
Jump to:  



You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Protected by Anti-Spam ACP
 
 


Theme by Dustin Baccetti
Powered by phpBB © 2001, 2002 phpBB Group

Copyright © MQSeries.net. All rights reserved.