Instructions for Incommon Cert Installation for IBM Spectrum Protect Clients


The certificate on IBM Spectrum Protect backup server sdc-busrv02.umd.edu will expire June 2, 2021 8:00:00 AM.  In order to prepare for a transition to a new root certificate provider, our testing has indicated that existing clients need to manually install the root and intermediate certificates for Incommon-signed certificates.  Please, follow the instructions below to install the certificate on each IBM Spectrum Protect client by 06/01/2021.

Determine if a system is impacted

Windows:

View the default dsm.opt (C:\Program Files\tivoli\tsm\baclient\dsm.opt) file for the following parameter and value:

TCPSERVERADDRESS sdc-busrv02.umd.edu

Linux:

View the dsm.sys (/opt/tivoli/tsm/client/ba/bin/dsm.sys) file for the following parameter:

TCPSERVERADDRESS sdc-busrv02.umd.edu

Root certificate installation for Windows TSM clients

1.

2.

   dsmcert.crl

   dsmcert.idx

   dsmcert.kdb

   dsmcert.rdb

   dsmcert.sth

3.

If you get the "ANS1592E Failed to initialize SSL protocol."

Root certificate installation for Unix/Linux servers 

  1. Navigate to the following directory: cd /opt/tivoli/tsm/client/ba/bin
  2. Run the following commands:
  3. To verify for TSM clients, run the following command:
    • dsmc q sched