Professional Documents
Culture Documents
Communication Settings
ltima actualizacin: February 4, 2014
Contents
Note: Endpoints use the +reportagent service account to connect to the Message
Queue.
The password that CA ControlMinder Enterprise Management and the DMS use to
connect to the Message Queue
Note: CA ControlMinder Enterprise Management and the DMS use the reportserver
service account to connect to the Message Queue.
Before you change the Message Queue administrator password, note the following:
The default password for this account is the communication password that you specify
when you install CA ControlMinder Enterprise Management.
Important! If you have more than one Distribution Server in your enterprise, first change the
password on the Distribution Server installed on the Enterprise Management Server, then change
the password on the other Distribution Servers in your enterprise. The Message Queue is part of
the Distribution Server.
To change the Message Queue administrator password, set the Message Queue password for the
admin user.
Example: Set the Message Queue Password For the admin User
This Tibco EMS Administration Tool command sets the Message Queue password for the admin
user. The password is "secret", and must be in clear text and enclosed in double quotes:
3. Navigate to the following directory, where DistServer is the directory in which you
installed the Distribution Server:
4. DistServer/MessageQueue/tibco/bin/ems
o password
Specifies the password for the server certificate.
8. Open the tibemsd.conf file in a text-based editor. The file is located in the following
directory:
9. DistServer/MessageQueue/tibco/bin/ems
o ssl_server_identity
Specifies the full path to the server certificate.
o ssl_server_key
Specifies the full path to the server certificate key.
Note: Leave this parameter blank if you use a .p12 certificate.
o ssl_password
Specifies the encrypted password for the server certificate.
ssl_server_identity = "C:\Program
Files\CA\AccessControlServer\MessageQueue\conf\keystore.p12"
ssl_server_key =
ssl_password = }>8:Jt^+%INK&i^v
You may need to regularly change the password for the Message Queue SSL keystore to comply
with your organization's security and password policies.
Before you change the password for the Message Queue SSL keystore, note the following:
The default password is the communication password that you specify when you install
CA ControlMinder Enterprise Management.
The password is stored in the following file, where ACServer is the directory in which you
installed CA ControlMinder Enterprise Management:
ACServer/MessageQueue/conf/keystore.p12
Important! If you have more than one Distribution Server in your enterprise, first change the
password on the Distribution Server installed on the Enterprise Management Server, then change
the password on the other Distribution Servers in your enterprise. The Message Queue is part of
the Distribution Server.
2. Open a command prompt window and navigate to the following directory, where JDK is
the directory in which you installed the Java Development Kit:
3. JDK/bin
o -genkey
Specifies that the command creates a key pair (public and private keys).
o -keyalg RSA
Specifies to use the RSA algorithm to generate the key pair.
o -keysize 1024
Specifies that the size of the generated key is 1024 bits.
o -storetype PKCS12
Specifies that the generated key is in the PKCS12 file format.
o -dname "cn=acmq"
Specifies that X.500 distinguished name for the generated certificate is acmq.
This name is used in the issuer and subject fields of the certificate.
o -alias acmq
Specifies to update the keystore entry names acmq.
o -storepass "password"
Specifies the password that protects the Message Queue SSL keystore. The
password must be identical to the password that you specify for the -keypass
parameter.
o -keypass "password"
Specifies the password that protects the private key of the new key pair. The
password must be identical to the password that you specify for the -storepass
parameter.
The keytool utility changes the password for the Message Queue SSL keystore.
7. Navigate to the following directory, where DistServer is the directory in which you
installed the Distribution Server:
8. DistServer/MessageQueue/tibco/bin/ems
The URL information is stored in the Message Queue in the following XML file,
where JBoss_HOME is the directory where you installed JBoss:
JBoss_home/server/default/deploy/jms/tibco-jms-ds.xml
1. Stop the JBoss Application Server, the CA ControlMinder Message Queue service and all
the CA ControlMinder services.
3. JBoss_home\server\default\deploy\jms
a. Locate localhost.
6. HKEY_LOCAL_MACHINE\SOFTWARE\ComputerAssociates\AccessControl\Common\
commmunication
7. Locate the key value Distribution_Server.
The default value is ssl://localhost:7243.