Jun 29

This is a follow-up on my previous post on creating certificates for WebSphere MQ.

In one of my customers environment we began having troubles connecting to SSL secured WMQ channels as we upgraded the WebSphere Message Broker Toolkit to version 6.1. After opening a ticket with IBM and getting quite a few groups within Big Blue involved, it turned out that starting with the IBM Java 1.5 JRE, they have added a validation on Basic Constraints for CA certificates. WMB 6.1 ships with Java 1.5. The scripts I published in my last post does not set this attribute. As far as I’ve been able to find, there is no workaround besides recreating your CA certificate, which means re-signing all your keys. This annoys me, but given that the requirement for setting the Basic Constraints has been in the RFC since before dawn, the blame is pretty much my own.

4.2.1.10  Basic Constraints                                            
                                                                       
   The basic constraints extension identifies whether the subject of the
   certificate is a CA and the maximum depth of valid certification    
   paths that include this certificate.                                
                                                                       
The cA boolean indicates whether the certified public key belongs to   
   a CA.  If the cA boolean is not asserted, then the keyCertSign bit in
   the key usage extension MUST NOT be asserted.                       
                                                                       
This extension MUST appear as a critical extension in all CA           
   certificates that contain public keys used to validate digital      
   signatures on certificates. 

Anyways, the script is now updated. The required change is to add the argument “-ca true” when creating the CA certificate.
If you have any further suggestions to improve the scripts, please contact me and I’ll make sure to upgrade them.

Jun 29
last.fm does REST API, FAIL
icon1 Niklas | icon2 Tags: , . | icon4 06 29th, 2008| icon3No Comments »

last.fm just launched their brand new API (via Fredrik). Sporting support for both XML-RPC and REST. Now that’s a first sign of warning. And unsurprisingly it turns out that the “REST” API is just another RPC over HTTP incarnation.

For example.:

http://ws.audioscrobbler.com/2.0/?method=artist.getSimilar&api_key=xxx...

If you are accessing a write service, you will need to submit your request as an HTTP POST request. All POST requests should be made to the root url:

http://ws.audioscrobbler.com/2.0/

WTF? Is it really that hard to get REST? To add insult to injury, they even managed to make up their own authentication protocol, despite, you know, OpenID and OAuth being fairly mainstream these days.

Jun 23
Tree hugger
icon1 Niklas | icon2 | icon4 06 23rd, 2008| icon34 Comments »


Tree hugger, originally uploaded by protocol7.

While mountain biking, try not to disagree with trees on the choice of direction.

Jun 6
Elvis is alive… in Varberg
icon1 Niklas | icon2 | icon4 06 6th, 2008| icon3No Comments »


Elvis is alive… in Varberg, originally uploaded by protocol7.