>Subject: Re: [sipx-users] SSL Cert help > >I will be glad to listen to a whole bunch of "I told so", but >I would greatly appreciate a little help first. >I made a system backup, and backed up the SSL directories >before trying any of this. I wanted to give an external SSL >cert one more shot. It didn't work, so I went to revert back >to a self signed cert. I follwed the same things I had done >before. I ran /usr/bin/ssl-cert/gen-ssl-keys.sh and then >/usr/bin/ssl-cert/install-cert.sh Most everything is ok, but I >can't change the PIN from a phone. I restored from backup >taken prior to any of this, and it didn't help. I get the >errors below in mediaserver_cgi.log I have tried regenerating >the certs a few times, and everything seems to go ok. Can >someone help me get past this issue? I would greatly >appreciate it and wil not tinker with ssl certs again until 4.2 :) > > >"2010-01-20T16:53:40.411617Z":1:KERNEL:ERR:nshpbx1.sipx.voip:pi >d-8800:23D69C30:mediaservercgi:"OsSSL::verifyCallback >invalid certificate at depth 0\n error='unable to get >local issuer >certificate'\n >issuer='/C=US/ST=AnyState/L=AnyTown/O=sipx.voip/OU=sipXecs/CN=c >a.nshpbx1.sipx.voip/[email protected]'\n >subject='/C=US/ST=AnyState/L=AnyTown/O=sipx.voip/OU=sipXecs/CN= >nshpbx1.sipx.voip/[email protected]'" >"2010-01-20T16:53:40.411754Z":2:KERNEL:ERR:nshpbx1.sipx.voip:pi >d-8800:23D69C30:mediaservercgi:"OsSSLConnectionSocket >SSL_connect failed: :\n SSL error: 1 >'error:00000001:lib(0):func(0):reason(1)'" >"2010-01-20T16:53:40.411797Z":3:HTTP:ERR:nshpbx1.sipx.voip:pid- >8800:23D69C30:mediaservercgi:"HttpMessage::get[4] >socket to 10.87.20.5:8101 not connected, retry 1 after 20ms" >"2010-01-20T16:53:40.433197Z":4:KERNEL:ERR:nshpbx1.sipx.voip:pi >d-8800:23D69C30:mediaservercgi:"OsSSL::verifyCallback >invalid certificate at depth 0\n error='unable to get >local issuer >certificate'\n >issuer='/C=US/ST=AnyState/L=AnyTown/O=sipx.voip/OU=sipXecs/CN=c >a.nshpbx1.sipx.voip/[email protected]'\n >subject='/C=US/ST=AnyState/L=AnyTown/O=sipx.voip/OU=sipXecs/CN= >nshpbx1.sipx.voip/[email protected]'" >"2010-01-20T16:53:40.433261Z":5:KERNEL:ERR:nshpbx1.sipx.voip:pi >d-8800:23D69C30:mediaservercgi:"OsSSLConnectionSocket >SSL_connect failed: :\n SSL error: 1 >'error:00000001:lib(0):func(0):reason(1)'" >"2010-01-20T16:53:40.433289Z":6:HTTP:ERR:nshpbx1.sipx.voip:pid- >8800:23D69C30:mediaservercgi:"HttpMessage::get[4] >socket to 10.87.20.5:8101 not connected, retry 2 after 40ms" >"2010-01-20T16:53:40.473894Z":7:HTTP:ERR:nshpbx1.sipx.voip:pid- >8800:23D69C30:mediaservercgi:"HttpMessage::get[4] >socket connection to 10.87.20.5:8101 failed, give up..." > > >On 1/20/2010 7:38 AM, Scott Lawrence wrote: >> On Wed, 2010-01-20 at 12:21 +0000, [email protected] wrote: >> >>> Scott - if there are issues, should they show up >immediately? If you >>> have to back out, is it still just as easy as regenerating the self >>> signed cert? >>> >> Yes, they should show up as soon as you restart. >> >> If you think regenerating the self signed cert is easy, then yes - >> it's just that easy.
Not sure if this will help but did you regenerate and install the Java Keystore/Truststore? If not you may want to try this first. Raymond _______________________________________________ sipx-users mailing list [email protected] List Archive: http://list.sipfoundry.org/archive/sipx-users Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-users sipXecs IP PBX -- http://www.sipfoundry.org/
