Ab 7.1.8 und 8.* ssl Verschlüsseldung.
Vor Upgrade auf Version alte cert.kdbs löschen und neu generieren lassen.
1))
Server Key auf Client importieren. (windows ggf. Commandline ALS ADMIN)
C:\Program Files\Tivoli\TSM\baclient>dsmcert.exe -add -server idmztsm1 -file IDMZTSM1.cert256.arm
List all certificates in the cert.kdb of the server
gsk8capicmd_64 -cert -list all -db cert.kdb -stashed
Server2Server Communication: Add a Certificate to the kert.db
gsk8capicmd_64 -cert -add -label 141.90.16.7 -db cert.kdb -stashed -file /tsm1/server/cert256.arm
List default Key from Keystore
tsm2:/ispt2/server # gsk8capicmd_64 -cert -getdefault -db cert.kdb -stashed Label : TSM Server SelfSigned SHA Key Key Size : 2048 Version : X509 V3 Serial : 05ccd2b3464abe23 Issuer : "CN=TSM Self-Signed Certificate,OU=TSM Network,O=TSM,C=US" Subject : "CN=TSM Self-Signed Certificate,OU=TSM Network,O=TSM,C=US" Not Before : July 4, 2018 1:38:16 PM GMT+02:00 Not After : July 2, 2028 1:38:16 PM GMT+02:00 Fingerprint :7140a6a4e3539dddddddddddddddddddddddddddddd
you need to remove the complete cert.db an add all certificates again
Stop any IBM Spectrum Protect administrator and backup-archive clients that are running on the affected system. From the client installation directory (default=C:\Program Files\Tivoli\TSM\baclient), remove the following files:
dsmcert.crl dsmcert.idx dsmcert.kdb dsmcert.rdb dsmcert.sth
rm dsmcert.crl dsmcert.idx dsmcert.kdb dsmcert.rdb dsmcert.sth