Hi all,
   I've been trying to setup an HA system (using s/w revision 14990) and
have been unable to get a distributed server going due to SSL
certificate issues.
   During the installation of the distributed server, 
 
   1. I identified it as a distributed server, 
   2. Went to the Primary and added the Distributed server (noting the
password generated)
   3. Continued with the installation of the distributed server by
entering the Master and then the appropriate password from step 2.
   4. Noticed that all necessary SSL keys were copied from the Master
(Primary).
   5. Started the Distributed server.

   Initially the distributed server showed the following errors:

Checking TLS/SSL configuration:                            [FAILED]
sipXpbx:
sipXpbx: sipXpbx configuration problems found:
sipXpbx:
sipXpbx: Check TLS/SSL configuration
sipXpbx:   SSL Certificate '/etc/sipxpbx/ssl/ssl.crt' is invalid as
client certi
ficate.
sipXpbx:       /etc/sipxpbx/ssl/ssl.crt:
/C=US/ST=AnyState/L=AnyTown/O=ca.nortel
.com/OU=scs/CN=bcmdesk7002.ca.nortel.com/[email protected]
a.nortel
.com
sipXpbx:       error 9 at 0 depth lookup:certificate is not yet valid
sipXpbx:   SSL Certificate '/etc/sipxpbx/ssl/ssl.crt' is invalid as
server certi
ficate.
sipXpbx:       /etc/sipxpbx/ssl/ssl.crt:
/C=US/ST=AnyState/L=AnyTown/O=ca.nortel
.com/OU=scs/CN=bcmdesk7002.ca.nortel.com/[email protected]
a.nortel
.com
sipXpbx:       error 9 at 0 depth lookup:certificate is not yet valid
sipXpbx:   SSL certificates:  /etc/sipxpbx/ssl/ssl.crt
sipXpbx:   Check failed for  /etc/sipxpbx/ssl/ssl.crt
/etc/sipxpbx/ssl/ssl.crt
sipXpbx:

   
    When I stopped and then restarted the server (using "service sipxecs
stop" following by "service sipxecs start") those problems didn't show.

    On the primary server, any replication to the distributed server
fails and the sipxconfig log file shows a number of SSL errors stating:

Caused by: java.security.cert.CertPathValidatorException: The
certificate issued by [email protected],
CN=ca.bcmdesk2073.ca.nortel.com, OU=scs, O=ca.nortel.com, L=AnyTown,
ST=AnyState, C=US is not trusted; internal cause is:
        java.security.cert.CertPathValidatorException: Certificate
chaining error



    Has anyone else seen this issue?  Seems odd that the primary doesn't
trust the certificate (which it generated) from the distributed server.


Thanks
Raymond
_______________________________________________
sipx-dev mailing list
[email protected]
List Archive: http://list.sipfoundry.org/archive/sipx-dev
Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-dev

Reply via email to