I will be glad to listen to a whole bunch of "I told so", but I would 
greatly appreciate a little help first.
I made a system backup, and backed up the SSL directories before trying 
any of this. I wanted to give an external SSL cert one more shot. It 
didn't work, so I went to revert back to a self signed cert. I follwed 
the same things I had done before. I ran 
/usr/bin/ssl-cert/gen-ssl-keys.sh and then /usr/bin/ssl-cert/install-cert.sh
Most everything is ok, but I can't change the PIN from a phone. I 
restored from backup taken prior to any of this, and it didn't help. I 
get the errors below in mediaserver_cgi.log
I have tried regenerating the certs a few times, and everything seems to 
go ok. Can someone help me get past this issue? I would greatly 
appreciate it and wil not tinker with ssl certs again until 4.2 :)


"2010-01-20T16:53:40.411617Z":1:KERNEL:ERR:nshpbx1.sipx.voip:pid-8800:23D69C30:mediaservercgi:"OsSSL::verifyCallback
 
invalid certificate at depth 0\n       error='unable to get local issuer 
certificate'\n       
issuer='/C=US/ST=AnyState/L=AnyTown/O=sipx.voip/OU=sipXecs/CN=ca.nshpbx1.sipx.voip/[email protected]'\n
       
subject='/C=US/ST=AnyState/L=AnyTown/O=sipx.voip/OU=sipXecs/CN=nshpbx1.sipx.voip/[email protected]'"
"2010-01-20T16:53:40.411754Z":2:KERNEL:ERR:nshpbx1.sipx.voip:pid-8800:23D69C30:mediaservercgi:"OsSSLConnectionSocket
 
SSL_connect failed: :\n   SSL error: 1 
'error:00000001:lib(0):func(0):reason(1)'"
"2010-01-20T16:53:40.411797Z":3:HTTP:ERR:nshpbx1.sipx.voip:pid-8800:23D69C30:mediaservercgi:"HttpMessage::get[4]
 
socket to 10.87.20.5:8101 not connected, retry 1 after 20ms"
"2010-01-20T16:53:40.433197Z":4:KERNEL:ERR:nshpbx1.sipx.voip:pid-8800:23D69C30:mediaservercgi:"OsSSL::verifyCallback
 
invalid certificate at depth 0\n       error='unable to get local issuer 
certificate'\n       
issuer='/C=US/ST=AnyState/L=AnyTown/O=sipx.voip/OU=sipXecs/CN=ca.nshpbx1.sipx.voip/[email protected]'\n
       
subject='/C=US/ST=AnyState/L=AnyTown/O=sipx.voip/OU=sipXecs/CN=nshpbx1.sipx.voip/[email protected]'"
"2010-01-20T16:53:40.433261Z":5:KERNEL:ERR:nshpbx1.sipx.voip:pid-8800:23D69C30:mediaservercgi:"OsSSLConnectionSocket
 
SSL_connect failed: :\n   SSL error: 1 
'error:00000001:lib(0):func(0):reason(1)'"
"2010-01-20T16:53:40.433289Z":6:HTTP:ERR:nshpbx1.sipx.voip:pid-8800:23D69C30:mediaservercgi:"HttpMessage::get[4]
 
socket to 10.87.20.5:8101 not connected, retry 2 after 40ms"
"2010-01-20T16:53:40.473894Z":7:HTTP:ERR:nshpbx1.sipx.voip:pid-8800:23D69C30:mediaservercgi:"HttpMessage::get[4]
 
socket connection to 10.87.20.5:8101 failed, give up..."


On 1/20/2010 7:38 AM, Scott Lawrence wrote:
> On Wed, 2010-01-20 at 12:21 +0000, [email protected] wrote:
>    
>> Scott - if there are issues, should they show up immediately? If you
>> have to back out, is it still just as easy as regenerating the self
>> signed cert?
>>      
> Yes, they should show up as soon as you restart.
>
> If you think regenerating the self signed cert is easy, then yes - it's
> just that easy.
>
>
>    

_______________________________________________
sipx-users mailing list [email protected]
List Archive: http://list.sipfoundry.org/archive/sipx-users
Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-users
sipXecs IP PBX -- http://www.sipfoundry.org/

Reply via email to