---
title: IBM® MQ for HPE NonStop 'How to' Series Part 2 - Using TLS Alias Cipherspecs
description: The TLS capability in MQ for HPE NonStop has recently been extended to include the ability to use the latest TLS 1.3 ciphers along with a new class of cipherspecs known as alias ciphers. Alias ciphers were introduced in the MQ for Windows, Linux and zOS products in MQ v9.1 and with the release of MQ v8.1 fixpack 7, they are also available on HPE NonStop.
image: https://insights.comforte.com/hubfs/Blog%20Header%20Images/cf_blog_post2_b-1.jpeg
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](https://insights.comforte.com/hpe-nonstop-solutions/)

[![ibm mq for hpe nonstop](https://insights.comforte.com/hubfs/Blog%20Header%20Images/cf_blog_post2_b-1.jpeg)](https://insights.comforte.com/hpe-nonstop-solutions/ibm-mq-for-hpe-nonstop-how-to-series-part-2-using-tls-alias-cipherspecs)

[Gerhard Lehnhoff](https://insights.comforte.com/hpe-nonstop-solutions/author/gerhard-lehnhoff) l May 27, 2021 at 4:00 PM l [Connectivity](https://insights.comforte.com/hpe-nonstop-solutions/tag/connectivity), [HPE Nonstop](https://insights.comforte.com/hpe-nonstop-solutions/tag/hpe-nonstop)

# IBM® MQ for HPE NonStop 'How to' Series Part 2 - Using TLS Alias Cipherspecs

For many years, MQ products have offered the ability to secure connections over MQ channels using TLS, i.e. Transport Level Security. TLS is the new name for what was previously known as the Secure Sockets Layer, or SSL. TLS technology is used in many scenarios today including many websites that offer it in the form of secure HTTPS connections. TLS provides authentication, integrity and privacy and is the preeminent security technology in today’s commercial world. When configured with TLS, MQ channels can securely send messages over an otherwise insecure network.

The TLS capability in MQ for HPE NonStop has recently been extended to include the ability to use the latest TLS 1.3 ciphers along with a new class of cipherspecs known as alias ciphers. Alias ciphers were introduced in the MQ for Windows, Linux and zOS products in MQ v9.1 and with the release of MQ v8.1 fixpack 7, they are also available on HPE NonStop.

## Traditional TLS channels

Setting up a standard TLS channel is relatively simple. The MQ administrator need only choose an available MQ cipherspec, configure both ends of the channel to use that cipherspec with the SSLCIPH attribute, and finally, provide suitable certificates for each participating queue manager.

The above recipe is well known and has been used for many years to setup secure production MQ channels. It is important to recognize that this type of deployment requires the same, specific TLS cipherspec to be configured at each end of the channel pair, like so:

At queue manager ALICE, we define a TLS sender channel like so:

      define channel (ALICE.TO.BOB) chltype(SDR) …… SSLCIPH(ECDHE\_RSA\_AES\_128\_CBC\_SHA256)

and its partner at queue manager BOB,

      define channel (ALICE.TO.BOB) chltype(RCVR) …… SSLCIPH(ECDHE\_RSA\_AES\_128\_CBC\_SHA256)

The same SSLCIPH choice (which in the example above is a modern TLS 1.2 cipherspec called ECDHE\_RSA\_AES\_128\_CBC\_SHA256) must be configured at each end of the channel-pair.

Doing this isn’t particularly onerous for a few channel-pairs but remember that TLS technology evolves and improves over time and the SSLCIPH choice that seemed reasonable today, will likely need to be reconsidered again in the near-future. MQ is regularly extended with new TLS cipher support and an MQ organization that wants to use the strongest security protocols will be planning to regularly review its TLS channels to remain current with these changes.

## Future-proofing your TLS channels using ALIAS ciphers

Using alias ciphers, we can define our MQ TLS channels so they don’t need to reconfigured as often. An alias cipher is the name for a class of MQ cipherspecs that share a common characteristic, namely their TLS protocol. Alias ciphers can be used in any channel’s SSLCIPH specification instead of a specific cipherspec name and using them can reduce the need to change the channel definition as MQ TLS features are rolled out.

These are the basic Alias Cipherspecs offered by MQ v8.1:

|    ANY |  Selects any enabled cipherspec |
| --- | --- |
|    ANY\_TLS12 | Selects any enabled cipherspec that uses the TLS 1.2 protocol |
|    ANY\_TLS13 |  Selects any enabled cipherspec that uses the TLS 1.3 protocol |

But, these are also provided:

|    ANY\_TLS12\_OR\_HIGHER |  Selects any enabled cipherspec that uses the TLS 1.2 protocol *or later* |
| --- | --- |
|    ANY\_TLS13\_OR\_HIGHER |  Selects any enabled cipherspec that uses the TLS 1.3 protocol *or later* |

The last two Alias ciphers are particularly interesting. Channel-pairs that use them (ANY\_TLS12\_OR\_HIGHER or ANY\_TLS13\_OR\_HIGHER) will automatically adapt to later, stronger, protocols and cipherspecs as new TLS features are added to MQ.

For example, here’s the previous ALICE and BOB channel’s, redrafted to take advantage of Alias ciphers:

At queue manager ALICE:

      define channel (ALICE.TO.BOB) chltype(SDR) …… SSLCIPH(ANY\_TLS12\_OR\_HIGHER)

and its partner at queue manager BOB,

      define channel (ALICE.TO.BOB) chltype(RCVR) …… SSLCIPH(ANY\_TLS12\_OR\_HIGHER)

## Cipherspec ordering

When using Alias ciphers, modern MQ products will choose the strongest protocol and cipherspecs as specified by the channel definition and the queue manager. When choosing cipherspecs, MQ has a preferred orders for its cipherspecs. This order is the same on different MQ platforms (Windows, Linux, zOS and now HPE Nonstop) and roughly proceeds from strongest to weakest.

This default order for cipherspecs is shown in [the MQ documentation here.](https://www.ibm.com/docs/en/mq-for-hpe-nonstop/8.1.0?topic=SSKM59_8.1.0/com.ibm.mq.hpnss.doc/ssl/q134760_.html)

Note that you can specify your own list of cipherspecs and specify a different preference order using the SSL: stanza and AllowedCipherSpecs attribute in the qm.ini file.

## Rcommended Reading

The following IBM MQ documentation discusses TLS channels and alias ciphers in more detail:

[https://www.ibm.com/docs/en/mq-for-hpe-nonstop/8.1.0](https://www.ibm.com/docs/en/mq-for-hpe-nonstop/8.1.0)

[https://www.ibm.com/docs/en/mq-for-hpe-nonstop/8.1.0?topic=v81-ssltls-channels](https://www.ibm.com/docs/en/mq-for-hpe-nonstop/8.1.0)

## Contact:

For more information on IBM MQ for HPE NonStop, please contact:

**Gerhard Lehnhoff**  
Director Business Unit IBM at comforte   
[g.lehnhoff@comforte.com](mailto:g.lehnhoff@comforte.com)

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/hpe-nonstop-solutions/ibm-mq-for-hpe-nonstop-how-to-series-part-2-using-tls-alias-cipherspecs&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/hpe-nonstop-solutions/ibm-mq-for-hpe-nonstop-how-to-series-part-2-using-tls-alias-cipherspecs&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/hpe-nonstop-solutions/ibm-mq-for-hpe-nonstop-how-to-series-part-2-using-tls-alias-cipherspecs&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/hpe-nonstop-solutions/ibm-mq-for-hpe-nonstop-how-to-series-part-2-using-tls-alias-cipherspecs&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/hpe-nonstop-solutions/ibm-mq-for-hpe-nonstop-how-to-series-part-2-using-tls-alias-cipherspecs&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Looking to improve connectivity on your HPE NonStop sytems?

Check out our [HPE NonStop connectivity page](https://www.comforte.com/solutions/hpe-nonstop/connectivity) to learn how. 

### Related posts

![IBM® MQ for HPE NonStop 'How to' Series Part 1 - Sharing a TLS Certificate Key Repository with Multiple Queue Managers](https://insights.comforte.com/hubfs/Blog%20Header%20Images/cf_blog_post2_b-1.jpeg)

 May 19, 2021 at 4:00 PM l [Connectivity](https://insights.comforte.com/hpe-nonstop-solutions/tag/connectivity) , [HPE Nonstop](https://insights.comforte.com/hpe-nonstop-solutions/tag/hpe-nonstop)

### [IBM® MQ for HPE NonStop 'How to' Series Part 1 - Sharing a TLS Certificate Key Repository with Multiple Queue Managers](https://insights.comforte.com/hpe-nonstop-solutions/ibm-mq-for-hpe-nonstop-how-to-series-part-1-sharing-a-tls-certificate-key-repository-with-multiple-queue-managers)

While MQ on Windows and Linux use a CMS keystore file usually called key.kdb, as their TLS key repository, MQ on HPE NonStop uses a different method; the TLS key repository for MQ on HPE NonStop is an OSS directory that contains TLS certificates and...

[Read more](https://insights.comforte.com/hpe-nonstop-solutions/ibm-mq-for-hpe-nonstop-how-to-series-part-1-sharing-a-tls-certificate-key-repository-with-multiple-queue-managers)

![IBM MQ Version 8 Functionality Now Available on HPE NonStop Platforms](https://insights.comforte.com/hubfs/blog%20header%20image%20man%20in%20server%20room.jpeg)

 July 6, 2020 at 4:00 PM l [Connectivity](https://insights.comforte.com/hpe-nonstop-solutions/tag/connectivity) , [HPE Nonstop](https://insights.comforte.com/hpe-nonstop-solutions/tag/hpe-nonstop)

### [IBM MQ Version 8 Functionality Now Available on HPE NonStop Platforms](https://insights.comforte.com/hpe-nonstop-solutions/ibm-mq-version-8-functionality-now-available-on-hpe-nonstop-platforms)

Further to our previous [article](https://offer.comforte.com/en/ibm-mq-for-hpe-nonstop?utm_campaign=HPE%20NonStop&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-9NNa1mXKpTzfRnIbyFDkbxxf_rLOXjBczNQPFuCVbI4SZHx1XdQ42eobNB_7LcfQcVvljO) about the general benefits of messaging using IBM MQ for HPE NonStop, this post outlines some of the specific technical new features when running or migrating to IBM MQ for HPE NonStop V8.1.IBM MQ has been available...

[Read more](https://insights.comforte.com/hpe-nonstop-solutions/ibm-mq-version-8-functionality-now-available-on-hpe-nonstop-platforms)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>