Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

remote loader and ssl

61 views
Skip to first unread message

Jude McCormick

unread,
Jan 26, 2004, 2:22:59 PM1/26/04
to
I'm having a new difficulty with SSL I can't find in the knowledgebase. I
have loaded IDM2 on a NW6.5 server and the remote loader service on a win3k
box. All was loading OK except password sync, so I went through the IM
admin guide and made sure I had everything set up okay. It told me enable
SSL communication on the remote loader in order to have password sync 2 work
correctly. After I added the kmo=certificate line to the driver properties
the remote loader would not connect anymore giving the following text in the
debug:

Loader: Waiting for DirXML to connect on 'TCP server socket, port 8090,
address xxx.xxx.xxx.xxx, using SSL'...

SSL protocol failure: error 14090086: SSL routine:
SSL3_GET_SERVER_CERTIFICATE: certificate verify failed.

I know I've validated the certificates and exported them correctly.

Thanks, Jude


Skipper

unread,
Jan 26, 2004, 2:50:05 PM1/26/04
to
Jude,

Have had the same thing.

Make sure that you export the right certificate.

Make sure that the kmo line reads kmo="yourcert - Servername"

In my case the cert was named Dirxml - FS1 forgot the - FS1

Skipper
Support Engineer

CNE / CCNA

Jude McCormick

unread,
Jan 28, 2004, 9:13:57 AM1/28/04
to
That worked somewhat. The error went away, but now when the remote loader
starts it just sits at:

Loader: Waiting for DirXML to connect on 'TCP server socket, port 8090,
address xxx.xxx.xxx.xxx, using SSL'...

No error messages, nothing. I let it sit for 24 hours and it did nothing.
I'm going to play with it some more today, but I'd love some suggestions.
Thanks, Jude

"Skipper" <xander.A...@spamlischgroep.nl> wrote in message
news:NbeRb.86$Wh...@prv-forum2.provo.novell.com...

Skipper

unread,
Jan 29, 2004, 4:41:32 AM1/29/04
to
Jude,

took the server about a minute to make the connection.

Have you restarted the dirxml driver on the NW server to activate the change?

Gary Clarkson

unread,
Jan 29, 2004, 8:34:09 PM1/29/04
to
I had the same error today, I didn't have 'cert - servername' i just had
cert - servername. They should put a browse button there for us
typing/syntax impaired people ;).

"Skipper" <xander.A...@spamlischgroep.nl> wrote in message

news:gz4Sb.2591$Wh....@prv-forum2.provo.novell.com...

Jude McCormick

unread,
Jan 30, 2004, 10:59:40 AM1/30/04
to
I had the quotes and I had restarted all my servers just to make sure. It
still never connected. I'm currently rebuilding it.

"Gary Clarkson" <gacl...@myrealbox.com> wrote in message
news:lwiSb.3425$Wh....@prv-forum2.provo.novell.com...

Perin Blanchard, DevNet SysOp 43

unread,
Jan 30, 2004, 11:29:55 AM1/30/04
to
You should not have the "- servername" in the KMO specification. The value
that names the KMO is called the "key pair name" and it is the portion of
the KMO object name that is before the "-" character.
--
Perin Blanchard, DevNet SysOp 43

"Jude McCormick" <jude.mc...@nhmccd.edu> wrote in message
news:MbvSb.3825$Wh....@prv-forum2.provo.novell.com...

Jude McCormick

unread,
Jan 30, 2004, 4:12:08 PM1/30/04
to
I reloaded it from scratch and I'm still having the same problem. This is
the error message I'm getting in the publisher status log:

java.io.ioexception: unable to read certificate, error 2612d194:kmo support
routines:ssl_ctx_use_kmo:reason (404), error 2612d198: kmo support routines:
ssl_ctx_use_kmo: reason (408)
no object name provided.

I can't find any information on this anywhere.

"Gary Clarkson" <gacl...@myrealbox.com> wrote in message
news:lwiSb.3425$Wh....@prv-forum2.provo.novell.com...

Matthias Lindner

unread,
Jan 31, 2004, 4:53:29 AM1/31/04
to

looks a bit like the something has no rights to read the certificate,
or doesn't exist.

are you sure, you did NOT export the 'public key certificate'
but the 'self signed certficate' instead ?
/* thats my personal opinion 'bout the first post in this thread,
because this results if you follow the documentation of IDM2
word by word
*/

in 'novell's guide to dirxml' they say, that the certificate should
be "in the same container as the ncp-server object running/hosting
the driver set". maybe it's just at the wrong place.

in the next version of IDM they'll hopefully create a wizard for
the AD certificate too.

Jude McCormick schrieb:

Jude McCormick

unread,
Feb 2, 2004, 10:20:07 AM2/2/04
to
I went back through and I had exported the wrong certificate so I
reconfigured all the connections with the correct certificate but I'm still
getting the exact same error message.


"Matthias Lindner" <matthias...@nospampleasevng.de> wrote in message
news:tWKSb.4382$Wh....@prv-forum2.provo.novell.com...

0 new messages