On Mon, Mar 23, 2009 at 3:24 PM, Raymond Dans <[email protected]> wrote:
> Hi all,
>   I've been trying to setup an HA system (using s/w revision 14990) and
> have been unable to get a distributed server going due to SSL
> certificate issues.
>   During the installation of the distributed server,
>
>   1. I identified it as a distributed server,
>   2. Went to the Primary and added the Distributed server (noting the
> password generated)
>   3. Continued with the installation of the distributed server by
> entering the Master and then the appropriate password from step 2.
>   4. Noticed that all necessary SSL keys were copied from the Master
> (Primary).
>   5. Started the Distributed server.
>
>   Initially the distributed server showed the following errors:
>
> Checking TLS/SSL configuration:                            [FAILED]
> sipXpbx:
> sipXpbx: sipXpbx configuration problems found:
> sipXpbx:
> sipXpbx: Check TLS/SSL configuration
> sipXpbx:   SSL Certificate '/etc/sipxpbx/ssl/ssl.crt' is invalid as
> client certi
> ficate.
> sipXpbx:       /etc/sipxpbx/ssl/ssl.crt:
> /C=US/ST=AnyState/L=AnyTown/O=ca.nortel
> .com/OU=scs/CN=bcmdesk7002.ca.nortel.com/[email protected]
> a.nortel
> .com
> sipXpbx:       error 9 at 0 depth lookup:certificate is not yet valid
> sipXpbx:   SSL Certificate '/etc/sipxpbx/ssl/ssl.crt' is invalid as
> server certi
> ficate.
> sipXpbx:       /etc/sipxpbx/ssl/ssl.crt:
> /C=US/ST=AnyState/L=AnyTown/O=ca.nortel
> .com/OU=scs/CN=bcmdesk7002.ca.nortel.com/[email protected]
> a.nortel
> .com
> sipXpbx:       error 9 at 0 depth lookup:certificate is not yet valid
> sipXpbx:   SSL certificates:  /etc/sipxpbx/ssl/ssl.crt
> sipXpbx:   Check failed for  /etc/sipxpbx/ssl/ssl.crt
> /etc/sipxpbx/ssl/ssl.crt
> sipXpbx:
>
>
>    When I stopped and then restarted the server (using "service sipxecs
> stop" following by "service sipxecs start") those problems didn't show.
>
>    On the primary server, any replication to the distributed server
> fails and the sipxconfig log file shows a number of SSL errors stating:
>
> Caused by: java.security.cert.CertPathValidatorException: The
> certificate issued by [email protected],
> CN=ca.bcmdesk2073.ca.nortel.com, OU=scs, O=ca.nortel.com, L=AnyTown,
> ST=AnyState, C=US is not trusted; internal cause is:
>        java.security.cert.CertPathValidatorException: Certificate
> chaining error
>
>
>
>    Has anyone else seen this issue?  Seems odd that the primary doesn't
> trust the certificate (which it generated) from the distributed server.


Any possibility that you have a full log with debug enabled?

Thanks



>
>
> Thanks
> Raymond
> _______________________________________________
> sipx-dev mailing list
> [email protected]
> List Archive: http://list.sipfoundry.org/archive/sipx-dev
> Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-dev
>



-- 
M. Ranganathan
_______________________________________________
sipx-dev mailing list
[email protected]
List Archive: http://list.sipfoundry.org/archive/sipx-dev
Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-dev

Reply via email to