Digital Developer Conference: a FREE half-day online conference focused on AI & Cloud – North America: Nov 2 – India: Nov 9 – Europe: Nov 14 – Asia Nov 23 Register now

Close outline
  • United States
IBM?
  • Site map
IBM?
  • Marketplace

  • Close
    Search
  • Sign in
    • Sign in
    • Register
  • IBM Navigation
IBM Developer Answers
  • Spaces
    • Blockchain
    • IBM Cloud platform
    • Internet of Things
    • Predictive Analytics
    • Watson
    • See all spaces
  • Tags
  • Users
  • Badges
  • FAQ
  • Help
Close

Name

Community

  • Learn
  • Develop
  • Connect

Discover IBM

  • ConnectMarketplace
  • Products
  • Services
  • Industries
  • Careers
  • Partners
  • Support
10.190.13.195

Refine your search by using the following advanced search options.

Criteria Usage
Questions with keyword1 or keyword2 keyword1 keyword2
Questions with a mandatory word, e.g. keyword2 keyword1 +keyword2
Questions excluding a word, e.g. keyword2 keyword1 -keyword2
Questions with keyword(s) and a specific tag keyword1 [tag1]
Questions with keyword(s) and either of two or more specific tags keyword1 [tag1] [tag2]
To search for all posts by a user or all posts with a specific tag, start typing and choose from the suggestion list. Do not use a plus or minus sign with a tag, e.g., +[tag1].
  • Ask a question

DFHWB0732 402 No common ciphers negotiated from gsk_secure_socket_init of SSL connection issue

550000W5JA gravatar image
Question by Rahulcoder007  (1) | Sep 11, 2018 at 02:47 PM securitycicscicstsssl

Hi, while trying to connect to a secure TLS 1.2 based fuse service via cics i am getting below mentioned issue:

DFHWB0732 402 No common ciphers negotiated from gsk_secure_socket_init of SSL connection issue

I checked other answers on this site but i am looking for more information like:

  1. How can i make sure that my cics is supporting TLS 1.2.

  2. How can i use trace so that actual error can be identified.

  3. How can i see which cipher is getting picked for that particular connection in cics.

Please revert o me asap.

Thanks in advance

People who like this

  0
Comment
10 |3000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster

1 reply

  • Sort: 
2000001H3B gravatar image

Answer by Theresa Hamilton (7202) | Sep 14, 2018 at 01:22 PM

H @Rahulcoder007
To ensure you are using TLS 1.2 use the MINTLSLEVEL=TLS12 parameter in your system initialization table (SIT).

Additional information about MINTLSLEVEL is in the CICS TS documentation under ENCRYPTION (DEPRECATED).

If you have the SIT parameter set correctly then you should use the following instructions to activate SSL trace:

  1. S GSKSRVR

  2. Restart CICS. NOTE: This only needs to be done if the problem is occurring at startup. If not, then CICS does NOT need to be restarted.

  3. Update GSKWTR PROC to add a dataset to hold the trace.

  4. TRACE CT,WTRSTART=GSKWTR

  5. TRACE CT,ON,COMP=GSKSRVR

  6. R n,JOBNAME=yyy),OPTIONS=LEVEL=255),WTR=GSKWTR,END where yyy is the name of CICS.

  7. Recreate the problem.

  8. TRACE CT,OFF,COMP=GSKSRVR

  9. TRACE CT,WTRSTOP=GSKWTR

  10. Send dataset from GSKWTR PROC.

To view the Trace use IPCS and enter command CTRACE COMP(GSKSRVR) FULL.

The SSL Trace will show the Ciphers used, the protocol level used and show you the error that caused the request to be rejected.

If you still need help then I would open open a IBM Service Request.

Posted on Behalf of Ron Lee
IBM CICS Level2 Support

Comment

People who like this

  0   Share
10 |3000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster

Follow this question

153 people are following this question.

Answers

Answers & comments

Related questions

CEMT PERFORM SSL REBUILD not picking up new certificate 1 Answer

Securing SSL outbound connection in CICS 2 Answers

Can we monitor DB2 functions like INSERT,UPDATE using CICS event publisher 2 Answers

CICS SSL connection with Basic authentication 4 Answers

CEMT PERFORM SECURITY REBUILD not refreshing Certificate changes in CICS 1 Answer

  • Contact
  • Privacy
  • IBM Developer Terms of use
  • Accessibility
  • Report Abuse
  • Cookie Preferences

Powered by AnswerHub

Authentication check. Please ignore.
  • Anonymous
  • Sign in
  • Create
  • Ask a question
  • Spaces
  • API Connect
  • Analytic Hybrid Cloud Core
  • Application Performance Management
  • Appsecdev
  • BPM
  • Blockchain
  • Business Transaction Intelligence
  • CAPI
  • CAPI SNAP
  • CICS
  • Cloud Analytics
  • Cloud Automation
  • Cloud Object Storage
  • Cloud marketplace
  • Collaboration
  • Content Services (ECM)
  • Continuous Testing
  • Courses
  • Customer Experience Analytics
  • DB2 LUW
  • Data and AI
  • DataPower
  • Decision Optimization
  • DevOps Build
  • DevOps Services
  • Developers IBM MX
  • Digital Commerce
  • Digital Experience
  • Finance
  • Global Entrepreneur Program
  • Hadoop
  • Hybrid Cloud Core
  • Hyper Protect
  • IBM Cloud platform
  • IBM Design
  • IBM Forms Experience Builder
  • IBM Maximo Developer
  • IBM StoredIQ
  • IBM StoredIQ-Cartridges
  • IIDR
  • ITOA
  • InformationServer
  • Integration Bus
  • Internet of Things
  • Kenexa
  • Linux on Power
  • LinuxONE
  • MDM
  • Mainframe
  • Messaging
  • Node.js
  • ODM
  • Open
  • PartnerWorld Developer Support
  • PowerAI
  • PowerVC
  • Predictive Analytics
  • Product Insights
  • PureData for Analytics
  • Push
  • QRadar App Development
  • Run Book Automation
  • Search Insights
  • Security Core
  • Storage
  • Storage Core
  • Streamsdev
  • Supply Chain Business Network
  • Supply Chain Insights
  • Swift
  • UBX Capture
  • Universal Behavior Exchange
  • UrbanCode
  • WASdev
  • WSRR
  • Watson
  • Watson Campaign Automation
  • Watson Content Hub
  • Watson Marketing Insights
  • dW Answers Help
  • dW Premium
  • developerWorks Sandbox
  • developerWorks Team
  • Watson Health
  • More
  • Tags
  • Questions
  • Users
  • Badges