IBMDO YOU?Hi, I'm MBO!

Settings

Make the site feel at home on your screen.

Theme

Loading your theme preference.

Keyboard shortcuts

Open search from anywhere, then move through the results without leaving the keyboard.

Open settings
Ctrl,or⌘,
Open search
CtrlKor⌘K
Select a search result
↑↓
Open the selected result
Enter
Close an open dialog
Esc

Invisible Bits of Maximo

Fix GSK_ERROR_BAD_CERT (gsk rc = 414)

Restore secure communication between the IBM HTTP Server plug-in and WebSphere by adding the correct WebSphere signer certificate to the plug-in key store.

I Beat Maximo — confirmed solution

Before you begin: this procedure changes the key store used by the WebSphere web server plug-in. Back up plugin-key.kdb, its stash file and the WebSphere configuration before continuing. Plan an IBM HTTP Server restart and test the change outside production first.

When the IBM HTTP Server plug-in cannot validate the certificate presented by WebSphere, Maximo requests can return HTTP 500 and http_plugin.log can contain this error:

Failed in r_gsk_secure_soc_init: GSK_ERROR_BAD_CERT(gsk rc = 414)

This article fixes the common case in which the plug-in's CMS key store does not contain the signer for the WebSphere application server's certificate. Error 414 can also indicate an expired, malformed or otherwise unacceptable partner certificate, so confirm the certificate shown in the plug-in log before changing the key store.

IBM documents this symptom in its GSK_ERROR_BAD_CERT troubleshooting note.

Identify the exact signer certificate

Sign in to the WebSphere administrative console.

WebSphere administrative console login page

Open Security > SSL certificate and key management.

WebSphere Security navigation showing SSL certificate and key management

Select Manage endpoint security configurations.

SSL certificate and key management page showing Manage endpoint security configurations

Expand Inbound, the cell and Nodes, then select the node that runs the Maximo application server. The example uses ctgNode01; use the node from your environment.

Inbound endpoint tree with the ctgNode01 node selected

Open Key stores and certificates.

Endpoint security page showing the Key stores and certificates link

Open NodeDefaultKeyStore, then select Personal certificates.

Node key-store list containing NodeDefaultKeyStore and NodeDefaultTrustStore

NodeDefaultKeyStore page showing the Personal certificates link

Open the chained personal certificate used by the application server. Record the signer certificate's common name and serial number from the certificate chain. Match both values; a common name alone is not enough to distinguish renewed or similarly named certificates.

Personal certificate chain showing the server and signer certificates

If http_plugin.log includes a PARTNER CERTIFICATE line, compare its distinguished name and serial number with this certificate. If they do not match, stop and identify the certificate actually presented to the plug-in.

Extract the signer from the node trust store

Return to Key stores and certificates, then open NodeDefaultTrustStore.

WebSphere breadcrumb returning to Key stores and certificates

Node key-store list with NodeDefaultTrustStore available

Select Signer certificates and locate the certificate whose name and serial number match the signer recorded above.

NodeDefaultTrustStore page showing the Signer certificates link

Signer certificate matching the application-server certificate chain

Select that certificate and choose Extract.

Signer-certificate toolbar containing the Extract action

Enter a temporary path and file name, choose a certificate data type supported by the target CMS key store, then select OK. Keep the file in a restricted location.

Extract signer certificate form containing the path, file name and data type

Confirm that WebSphere reports a successful extraction and that the file exists at the specified location.

WebSphere message confirming that the certificate was extracted

Extracted signer certificate visible in Windows Explorer

Add the signer to the plug-in key store

Return to Manage endpoint security configurations.

WebSphere breadcrumb returning to Manage endpoint security configurations

Under the same node, expand Servers and select the web server definition. The example uses webserver1; select the definition used by your IBM HTTP Server plug-in.

Endpoint tree with the webserver1 web server selected

Open Key stores and certificates, then open CMSKeyStore. This WebSphere resource represents the plug-in's plugin-key.kdb file.

Web server endpoint page showing the Key stores and certificates link

Web server key-store list containing CMSKeyStore

Open Signer certificates, select Add, then provide a unique alias and the path to the extracted signer certificate. Check the certificate details again before saving the master configuration.

CMSKeyStore page showing the Signer certificates link

Add signer certificate form containing the alias and certificate path

Repeat the signer comparison and import for every application-server node whose certificate chain is not already trusted by this plug-in key store. Nodes that present the same personal certificate need the matching signer only once.

IBM's plug-in signer procedure documents this signer exchange and confirms that CMSKeyStore maps to plugin-key.kdb.

Copy the key store to IBM HTTP Server

Open Servers > Server Types > Web servers.

WebSphere navigation showing the Web servers application

Select the web server definition, then open Plug-in properties.

WebSphere web-server list with webserver1 selected

Web server configuration page showing the Plug-in properties link

Select Copy to Web server key store directory. This propagates the repository copy of the key store and stash file to a managed web server.

Plug-in properties page showing Copy to Web server key store directory

For a remote or unmanaged web server, copy the files using your approved deployment process and preserve their permissions. IBM's WebSphere 9 plug-in SSL documentation notes that the key store must be copied to the web server before the plug-in can use it.

Restart IBM HTTP Server so the plug-in reloads the key store.

Windows Services showing IBM HTTP Server being restarted

Open Maximo through IBM HTTP Server and confirm that the request no longer returns HTTP 500. Check http_plugin.log for a successful connection and verify that no new GSK_ERROR_BAD_CERT or PARTNER CERTIFICATE validation errors appear. Remove the temporary extracted certificate according to your organisation's certificate-handling policy.

Find the fix

Search articles

Esc

Search titles, technical terms or error codes.