Welcome to the Calyx Software Message Boards where you can share ideas and solutions with other Calyx users! Calyx personnel including Tech Support, Development, QA, and Business Planning often visit these message boards unofficially to better understand our customers' needs. To submit your suggestions Click Here.
This discussion forum is a service provided by Calyx Software. Calyx Software does not endorse any particular point of view expressed in this forum or any information provided in it. The use of the information provided by other users in this message board is at your own risk.
Calyx Software Message Board
Home      Members   Calendar   Who's On
Welcome Guest ( Login | Register )
      



Problem testing the account in Point...Expand / Collapse
Author
Message
Posted 8/9/2005 9:53:27 PM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: Forum Members
Last Login: 9/13/2005 3:49:29 PM
Posts: 5, Visits: 6
Hi,

Just installed this new PDS and it seems fantastic but as I near the completion of this journey I am getting this problem which I am sure is easily resolved but figured someone else will run into it and might as well post it here.

I am running PDS 5.1 on a windows 2003 enterprise server running SQL 2000 enterprise with SP4 and all is working correctly. I have installed PDS and point and all imports and syncs are completed with flying colors. I have setup this server in a certificate Auth cluster and issued a certificate called pdata for server fileserver and installed it in C:\ so far so good. I can login to admin and do all the necessary functions like create assign secure users and groups. 

when going into point administrator I am trying to link it to the PDS server which is https://myserver/service  I have also tried https://myserver/pds/service with no love

I get this message  " the underlying connection was closed : could not establish trust relationship with the remote server "

Now strangely enough this happens even if I type https://myserver/blahblahbs or any other garbled garbage path. So it makes me wonder why it wont auth.  This is most likely something simple but I have checked all angles so what am I missing. Any help would be great.

Nathan Clark
Network Operations
Point Lending / Jennwell Corporation
nathan@pointlending.com
http://www.pointlending.com

Post #118
Posted 8/10/2005 7:07:46 AM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: Forum Members
Last Login: 9/13/2005 3:49:29 PM
Posts: 5, Visits: 6
Just an update on the situation. I have since narrowed the issue to my SSL certificate as I first suspected but still dont know why. I have ready some good articles after googling the error. My question is why is calyx trying to force us to use a purchased certificate. They have NO directions for using a selfsignedf (atleast as far as I saw) This is an internal system and should function correctly with or without SSL but yet they have have a nice certificate purchase program conveniently in place. If I have to purchase a certificate to get this working correctly you better believe my PDS will be overnighted BACK to calyx...... Well anyways I have tried several editing techniques of my certificate to open up the range of use and upon that I get a decompression SOAP error and of course theres no mention of this anywhere but being a programmer I use soap from time to time for .net apps and I think I am just gonna call tech support and see what they can do cause I have had little sleep and am begining to get grumpy......

Nathan Clark
Network Operations
Point Lending / Jennwell Corporation
nathan@pointlending.com
http://www.pointlending.com
Post #120
Posted 8/10/2005 10:20:14 AM


Supreme Being

Supreme Being

Group: Moderators
Last Login: 12/21/2008 11:16:31 PM
Posts: 837, Visits: 1,901
You can use PDS in an Intranet environment.  Does the common name on the certificate match the name in the URL?  So if your Service URL is https://myserver/service, then the common name should be "myserver".

Bryan
Point Product Manager
Post #128
Posted 8/10/2005 11:21:06 AM


www.ehuna.org

www.ehuna.orgwww.ehuna.orgwww.ehuna.orgwww.ehuna.orgwww.ehuna.orgwww.ehuna.orgwww.ehuna.orgwww.ehuna.org

Group: Administrators
Last Login: 12/17/2008 10:36:11 PM
Posts: 258, Visits: 13,336
Hi Nathan,

From what I understand you did not purchase your SSL certificate, but you created it on your own, sigining it yourself.  In this case, your client doesn't "trust" your SSL certificate until you update it with the appropriate Certificate Authority (CA).

Here are the steps to fix this:

1) On one of your client machines, close all of your browsers.
2) Open a browser and point it to your PDS Administration site (it should be something like https://myserver/admin).  Are you getting an SSL warning from within IE?  If yes, your client is not trusting the SSL certificate.  We must fix this before Point can securely connect to PDS.
3) What did you use to generate your certificate?  If you used Microsoft Certificate Server you can use the "Retrieve the CA certificate or certificate revocation list" option in the first page and then choose "Download CA certification path".  You'll end up with a *.p7b file.
4) Install the CA certificate on your client (you will need to look up the documentation to do so).
5) Close all of your browsers, open a new one and point it to https://myserver/admin.  You should now not get the SSL certificate warning (since your client now has your CA certificate and "trusts" your self signed certificate).
6) Open up Point Administrator and configure it to point to https://myserver/service.  You should now not get the "could not establish trust relationship with the remote server" error.

Note: if you self sign a certificate, you will need to install the CA certificate on every client computer where Point will be running.  This is by design: if anyone could sign their own certificate and it was automatically accepted by all browsers and clients in the world, there wouldn't be much of a point in creating SSL certificates.

That's one of the reasons Calyx provides a service for its customers so you can easily purchase and install a "real" SSL certificate that is trusted by all clients without additional setup.

If you'd like to avoid installing your CA certificate on every client, check out the following:

Q10168 - INFO: (v5.1) Appendix L - SSL Certificate
http://pdskb.calyxsoftware.com/article.aspx?id=10168

Calyx Software Secure SSL Services
http://ssl.calyxsoftware.com.

Hope this helps,

Emmanuel



Disclaimer
: this post carries no explicit or implied warranty. Nor is there any guarantee that the information contained in this post is accurate. It is offered in the hopes of helping others, but you use it at your own risk. The author will not be liable for any damages that occur as a result of using this post.

Post #129
Posted 9/1/2005 12:14:27 PM
Forum Newbie

Forum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum NewbieForum Newbie

Group: Forum Members
Last Login: 9/13/2005 3:49:29 PM
Posts: 5, Visits: 6
Hehe figures. Yeah I figured all this out after going back through and checking on my SSL settings.  Bween a while since I messed with SSL but it works fine. Thanks for the help.

Nathan Clark
Network Operations
Point Lending / Jennwell Corporation
nathan@pointlending.com
http://www.pointlending.com
Post #442
« Prev Topic | Next Topic »


Reading This TopicExpand / Collapse
Active Users: 0 (0 guests, 0 members, 0 anonymous members)
No members currently viewing this topic.
Forum Moderators: Emmanuel Huna, Bryan Telford, Jason Beck, Mike Thompson, BetaFisch

PermissionsExpand / Collapse

All times are GMT -8:00, Time now is 9:42am

Powered by InstantForum.NET v4.1.4 © 2009
Execution: 0.141. 16 queries. Compression Enabled.
© 2005 Calyx Software. All rights reserved.