Page 1 of 1

TM1 10.1.1 change SSL

Posted: Wed Nov 16, 2016 3:52 pm
by Maxime
Hi all,

I try to change SSL in developement server for one custosmer on TM1 server 10.1.1.

I have follow IBM process with updater kit :
http://www-01.ibm.com/support/docview.w ... wg21991789

After i have the good certificat in 3 folders SSL and i have uninstallSSL.bat and importsslcert.exe after.

I have set DEBUG mode for TM1 Admin server and I see this log with error.

Code: Select all

6444   DEBUG   2016-11-16 15:22:56,993   TM1.Server   Logger initialized
6444   DEBUG   2016-11-16 15:22:56,993   TM1.Event   mt_SetEvent: Set event 0x000000000000000C succeeded.
21056   DEBUG   2016-11-16 15:22:56,993   TM1.Event   mt_WaitForSingleObject: Successful for event 0x000000000000000C.
21056   DEBUG   2016-11-16 15:22:56,993   TM1.Event   mt_CloseEvent: Release of event 0x000000000000000C was successful.
21056   INFO   2016-11-16 15:22:57,039   TM1.Comm   Hostname for the admin server is "XXXXXXXXXX"
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   --- Configuration ---
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   Non-SSL port number: 5495
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   SSL port number: 5498
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   Support non-SSL clients?: False
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   Diffie-Hellman 1024 bit key file location: D:\Program Files\ibm\cognos\tm1\bin64\ssl\dh1024.pem
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   Diffie-Hellman 512 bit key file location: D:\Program Files\ibm\cognos\tm1\bin64\ssl\dh512.pem
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   Certificate file location: D:\Program Files\ibm\cognos\tm1\bin64\ssl\tm1admsvrcert.pem
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   Certificate revocation file location: 
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   Export certificate?: False
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   Export key ID: 
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   Certificate ID: tm1adminserver
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   Private key password file location: D:\Program Files\ibm\cognos\tm1\bin64\ssl\tm1cipher.dat
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   Password key file location: D:\Program Files\ibm\cognos\tm1\bin64\ssl\tm1key.dat
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   Certificate authority file location: D:\Program Files\ibm\cognos\tm1\bin64\ssl\applixca.pem
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   IP Version: IPv4
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   Heartbeat Interval: 10 seconds
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   Heartbeat Delay Interval: 10 seconds
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   IP Address: 172.16.4.99
21056   INFO   2016-11-16 15:22:57,039   TM1.TM1AdmSvr   Windowless?: False
21056   DEBUG   2016-11-16 15:22:57,039   TM1.Comm   Protocol for the admin server is tcp
21056   DEBUG   2016-11-16 15:22:57,039   TM1.Server.Memory   al_OpenPool() - apifunc# "0" - pool# "185" - Address "0x0000000000830000"
21056   DEBUG   2016-11-16 15:22:57,039   TM1.Server.Memory   al_OpenPool() - apifunc# "0" - pool# "185" - Address "0x0000000000830100"
21056   DEBUG   2016-11-16 15:22:57,321   TM1.Comm.SSL   Message in file: ..\tm1_r7s\OpenSSLCommon.c Line: 197 Msg: -Error with certificate at depth: 0 issuer = /C=US/ST=Massachusetts/L=Westboro/O=Applix, Inc./OU=Applix, Inc. subject = /C=US/ST=Massachusetts/O=Applix, Inc./OU=Applix, Inc./CN=tm1adminserver err 20:unable to get local issuer certificate
21056   DEBUG   2016-11-16 15:22:57,321   TM1.Comm.SSL   Message in file: ..\tm1_r7s\Sys_net.c Line: 4453 Msg: Error connecting SSL objectOpenSSL error code: 336134278 in .\ssl\s3_clnt.c line 984.
21056   DEBUG   2016-11-16 15:22:57,321   TM1.Server.Memory   al_FreePool  -  apifunc# "0" - pool# "0" - poolsize "37152.000000"
21056   INFO   2016-11-16 15:22:58,321   TM1.TM1AdmSvr   Admin server started as a service
In my instance TM1, it try to connect with admin server but it can't connect with admin server.

Code: Select all

39860   []   INFO   2016-11-16 16:24:56.571   TM1.Server   TM1 Server load time (secs) = 3
9804   []   INFO   2016-11-16 16:25:53.336   TM1.Server    Notifier le serveur d'administration
9804   []   INFO   2016-11-16 16:26:53.383   TM1.Server    Notifier le serveur d'administration
9804   []   INFO   2016-11-16 16:27:53.477   TM1.Server    Notifier le serveur d'administration
9804   []   INFO   2016-11-16 16:28:53.508   TM1.Server    Notifier le serveur d'administration
9804   []   INFO   2016-11-16 16:29:53.649   TM1.Server    Notifier le serveur d'administration
9804   []   INFO   2016-11-16 16:30:53.711   TM1.Server    Notifier le serveur d'administration
9804   []   INFO   2016-11-16 16:31:53.743   TM1.Server    Notifier le serveur d'administration
9804   []   INFO   2016-11-16 16:32:53.774   TM1.Server    Notifier le serveur d'administration
Can you have an idea for solve error and change SSL certificat in TM1 10.1.1.

I don't find a answer who solve my problem.

Thank for your time !

Re: TM1 10.1.1 change SSL

Posted: Wed Nov 16, 2016 4:09 pm
by gtonkin
Do you see the TM1 instance in Server Explorer?
Have you tried setting Support non-SSL clients to True to see if you can log in?

Re: TM1 10.1.1 change SSL

Posted: Wed Nov 16, 2016 4:17 pm
by BrianL
Did you run importsslcert.exe as administrator? Looks like the certificates aren't properly registered on the server machine.

Re: TM1 10.1.1 change SSL

Posted: Wed Nov 16, 2016 5:04 pm
by Maxime
Yes I have run importsslcert.exe as adminitrator.
I see the good certificat in certmgr => Trusted Root Certification Authorities => Certificates with expiration date 15/06/2026 for Applix, Inc.

[Solve] TM1 10.1.1 change SSL

Posted: Thu Nov 17, 2016 9:17 am
by Maxime
Thank all !

I have solve this my problem.

Re: TM1 10.1.1 change SSL

Posted: Thu Nov 17, 2016 9:22 am
by gtonkin
Please can you share the solution for future readers.