Android Client working on WPA2 PEAP without certificate loaded

I am trying to figure out why the andriod phone will work on our Cisco WPA2 Enterprise PEAP wireless when we use a custom internal certificate for authentication with our Cisco 1200 series AP's, ACS 4.x, and AD user group/accounts. 
The certificate is not loaded on the client, nor from what I learned is very difficult to import for use when trying to install a MS generated certificate
I did debugs between my regular Domain computer which has the domain certificate, and the Andriod and collected captures; see attachment tabs.
I do see that the certificate is used somehow and I do see what looks like a ldap lookup.
See the attached xls sheet with a debug tab for each the PC and the android.
I stripped out any sensitive account/domain info for viewing.
I'm not sure if this is a potential security loophole or not and welcome a discussion on this.

Really?
Its been a long time since I set this up and tested this and understood all the components. I just read up on it again and it appears your correct that PEAP only requires the server (ACS) side cert and the users credentials are protected during logon within MSCHAPv2.
If I recall, When I set up our enviroment, we had to install our domain cert on Pocket PC's (warehouse scanners), to get them to work with PEAP as the cert was not from a default trusted publisher. I don't understand why this was an issue then. Any ideas?
Our AD client computers all get the root cert by default, and all we do is push the wireless setting to the client by GP.
I was under the impression that we were protected by the client requiring the domain cert, and that pocket PC's, and other rogue wireless devices would not work without them. So how to best control rogue devices without using some NAP system?

Similar Messages

  • [WLAN] Use 802.1x with PEAP without Certificates?

    Hello there,
    is it possible to use 802.1x with PEAP authentication via MS-CHAPv2 without cheking for the servers certificate? I can't find an option to disable it

    On whitch device? You can set the autorithy certifacte to none or choose one from the list.
    ‡Thank you for hitting the Blue/Green Star button‡
    N8-00 RM 596 V:111.030.0609; E71-1(05) RM 346 V: 500.21.009

  • WPA2 Enterprise Authentication Without Certificate

    Dear All,
    I have Wifi Network, with WPA2 and Digital Certificate and EAP Protected EAP Authentication/Radius server Microsoft ISA
    I have tryed with the last Wifi Pc driver to connect at the network,  and I see that the PC  connect using only the Username and password, without configure the Certificate on the Client!
    After some Googleing I found that I should use the plus per-user certificates and EAP-TLS to solve the problem. It is true?
    Best Regards,
    Igor.

    Hi ifabrizio      
    Might be a bit concerning that you are able to connect to the network using only user name and password!
    EAP-TLS or PEAP solutions should be configured to leverage digital certificates for hardware trust identity.    
     "Authenticate as computer when computer information is available" to enable "Machine Authentication" AKA "Computer Authentication". Machine Authentication allows your PC to connect to the network by authenticating as "Computer" before a legitimate user logs in. This allows a machine to obtain group policies just like it was connected to a wired network and this is a unique feature of the Windows Client.
    If you don't have "Machine Authentication", your Group Policy will not function and non-cached users cannot log on to your machine even if they are given the proper permissions at the Domain level. "Machine Authentication" is needed to recreate the full "Wired" experience. In order for "Machine Authentication" to work, PEAP only requires that a Computer is joined to the domain. The computer will use its "Computer Password" to log on to the network. Note that for EAP-TLS or PEAP-EAP-TLS (stronger alternatives to PEAP) to work the computer must have a "Machine Certificate" installed from the Enterprise Root CA.
    Hope this helps.
    Jay

  • LDAP database without certificate

    hi
    Is there any type of eap protocol in ACS 4.1 works without certificates and compatible with LDAP database.
    thanks

    Hi,
    PEAP(EAP-GTC) works with LDAP, compatibility table,
    http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs41/user/overvw.htm#wp858207
    Configure ACS for PEAP authentication.
    http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a0080545a29.shtml
    And when it comes to configure client, generally I have seen with Intel clients, you have an option to uncheck "Validate Server Certificate" under "PEAP Server" section if you do not want to install CA root certificate on every client, after you have selected Authentication type as PEAP and authentication protocol as GTC under "PEAP User" section.
    Regards,
    Prem

  • SOAP Receiver with HTTPS(without certificate)

    Hi experts
    Receiver system not using any certificate.  Without certificate How PI can send message through HTTPS using SOAP.
    How to choose HTTPS transport protocol. (Here Target Url have Https://.....)
    Here I am using PI7.1 EHP1.
    I configured Receiver SOAP CC as
    Transport protocol as HTTP
    Taget Url https://api-demo.e-xact.com/transaction
    It will work? if not how to enable Https in SOAP receiver
    but I am getting below error In adapter
    Adapter Framework caught exception: iaik.security.ssl.SSLCertificateException: Peer certificate rejected by ChainVerifier
    Thank you
    Srini

    Hi Srini,
    The main reasons for this error "Peer certificate rejected..." be appearing are the following:
    1. The correct server certificate could not be present in the TrustedCA keystore view of NWA. Please ensure you have done all the steps described in the URL below:
    Security Configuration at Message Level
    http://help.sap.com/saphelp_nwpi711/helpdata/EN/ea/c91141e109ef6fe10000000a1550b0/frameset.htm
    2. The server certificate chain contains expired certificate. Check for it (that was the cause for other customers as well) and if it's the case renew it or extend the validation.
    3. Some other customers have reported similar problem and mainly the problem was that the certificate chain was not in correct
    order. Basically the server certificate chain should be in order Own->Intermedite->Root. To explain in detail, if your server certificate is A which is issued by an intermediate CA B and then B's certificate is issued by the C which is the root CA (having a self signed certificate).
    Then your certificate chain contains 3 elements A->B->C. So you need to have the right order of certificate in the chain. If the order is B first followed by A followed by C, then the IAIK library used by PI cannot verify the server as trusted. Please generate the certificate in the right order and then import this certificate in the TrustedCA keystore view and try again. Please take this third steps as the principal one.
    4. If the end point of the SOAP Call(Server) is configured to accept a client certificate(mandatory), then make sure that it is configured correctly in the SOAP channel and it is also within validity period.
    (This certificate is the one which is sent to Server for Client authentication)
    As a resource, you may need to create a new SSL Server key.
    The requirement from SAP SSL client side is that the requested site has to have certificate with CN equal to the requested site.  I mean if I request URL X then the CN must be CN=X.
    In other words, the CN of the certificate has to be equal to the URL in the ftp request. This can be the IP address or the full name of the host.
    Request the url with the IP of the SSL Server and the certificate to be with CN = IP of the server.
    In any other case the SSL communication will not work.
    Regards,
    Caio

  • Agentry Android Client Error

    Hi,
    I'm working on SMP 2.3 SP02 and using 6.1.2 Agentry Server, 6.1.2 Android Client. If Android device system language is English, Agentry Client works correctly. But when i change device system language, client gives error during transmit and shuts down.
    I've tried SP03 and SP04 but they both did not work.
    Thanks,
    Serkan Demir

    Hi Serkan,
    I have analyzed the issue of the problem.
    The problem of your error is as follows.
    When you transmitted your client or Android Agentry client (whatever version you use: 4.4, 4.4.2, 7.0.5.7, 7.0.6.2.48) is failing due to the client saw an updated definition from the server. The application is trying to download the new set of definition but your localized files are not properly loading.
    Your localizations/<overrideFiles>.tr.ini stated that you are not using any locale values ''. This means you are only using the named Country language - "tr".
    With this statement, you need to provide the needed override files for all the localization ini files.
    This includes the Enable.ini. You need to get Enable.tr.ini. In short, you need to make sure the Agentry system loads all the localizations properly. You need to make sure that nothing gets skipped.
    The main issue with skipping is that your timeStamp listed in your system showed that the definition is newer than your <OverrideFiles>.tr.ini.  This causes the application to try to load the application but due to your localization is not loading it is getting confuse and is failing on conversion.
    The technique is to play with the timeStamp of your application definition versus the override base files. The check Style is in Turkish but your localization files is not loaded so the conversion fails and you get the error (11).
    Potential actions:
    1. So you have to somehow work the system where you may try to load the application in English first (no conversion).
    2. So the application Check Style gets loaded without conversion.
    3. Then try to turn on your localization so that the application will start converting without downloading the application anymore.
    Another option:
    1) It could also be that your overrideFiles.tr.ini timeStamp has a time older than your application definition.
    2) You need to check the timeStamp of your overrideFiles.tr.ini and compare this to your Application/Development/<yourApplication> timeStamp.
    3) Check which one is newer.
    4) From the timeStamp determine why would the application load first before the override.
    5) As stated in my potential action above, we have to work the system to see how the application gets loaded so that conversion happens after the application update (probably on 2nd sync).
    Remember your error is that all your overrideFiles.tr.ini needs to be successfully loaded and not skipped. If you can do this it will work. Then you have to worry about other stuff that you need to do:
    A) Like making sure you have enabled the SAP language to sync with your SMP server. See http://service.sap.com/sap/support/notes/2116194 (for how to sync SAP timeZone with SMP test case).
    B) Setup your timeZoneAlias for your Android client to match SMP or SAP http://service.sap.com/sap/support/notes/1813025
    A and B step required in most time zone setup.
    Hope this helps.
    Mark Pe
    SAP Senior Support Engineer

  • Subsite security trimming in the Office365 for Android client

    I just installed the Android Office365 client and noticed that subsite links are not security trimmed. Is this by design or can I influence this by settings in Sharepoint Online? If I click a subsite link I don't have permissions to I get the error "Can't
    complete task. Office Mobile encountered a problem."
    Just noticed this behaviour only applies if you're member at a site, then you'll see the links to all subsites in the Android client, even those you don't have permissions to. In the web interface those links are trimmed. If you only have visitor rights
    at the suprasite you only see the subsite links you have permissions for in the Android client.

    Hi,
    According to your post, my understanding is that you failed to click a subsite link in the Office365 for Android client.
    I rececomend to set a user as administrator and then sign in the site using the account to check whether it works.
    This forum is supproted for SharePoint On-Primse. Regarding SharePoint Online, for quick and accurate answers to your questions, it is recommended that you initial a new thread in Office 365 forum.
    Office 365 forum
    http://community.office365.com/en-us/forums/default.aspx
    Thanks,
    Linda Li                
    Forum Support
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Linda Li
    TechNet Community Support

  • How to integrate 3D visual viewer with agentry android client

    Dear experts,
    I am working on SAP Work Manager 6.2,  integrating 3D visual viewer with agentry android client.
         - 3D Visualization is working with my WPF client
         - 3D Visualization is failing with my Android client (see below)
         - GIS is working on the same Android client.
    SAP® EAM and service mobile app SDK Installation Guide" version 1.0  indicates in step 5 to "Add Visual Enterprise libraries to the MobileAppsVELibrary project".  Could you confirm that this step is equivalent to copy contents of "DVL/Android/libs/" to libs folder of the MobileAppsVELibrary project? Is there other DLLs to copy in this step?
    3D Visualization on Android problem description:
    Code Levels:
    Eclipse => Luna 4.4.0 + ADT 23.0.4
    Agentry SDK => SMPAgentryClientFramework-Android-70.5.1.10.zip
    Mobile Apps Open UI SDK 1.0 => 51048778_5.zip
    SAP 3D SDK => SAP3DVisualEnterpriseApplicationsSDKv2_1.zip
    PB description:
    If I display VDS attachment, the screen is blank.
    ( If I display the 2nd attachment (image/jpeg), the image is displayed successfully on the Android device )
    ( If I click on the Locations link , the map is displayed successfully )
    I do not see an error the the android log.
    I am also getting some encrypted information on the Android client when I double click the blank screen and hit left/right arrows
    Regards.
    Regards.

    Hi Kunal,
    Thanks for your help. How do I checked that I have properly included the DVL libraries?
    I have implemented the following steps: (text in italic is extracted from the SAP® EAM and service mobile app SDK Installation Guide" )
    Thanks again. Didier.
    1. Add the Agentry SDK - Follow the instructions from the Open UI SDK documentation to set up the Android environment with Agentry Open UI projects in Eclipse.
    2. Add Common Library project in Eclipse
    3. Add VE Library project in Eclipse
    I have created the following projects from the files
    SMPAgentryClientFramework-Android-70.5.1.10.zip
    Mobile Apps Open UI SDK 1.0.51048778_5.zip
    b. Add MobileAppsVELibrary as a library in the AgentryAndroidClientSolution project.
    c. Copy the activities declaration
     AndroidManifest.xml
    4. Add VE Resources Library project in Eclipse
    5. Add Visual Enterprise libraries to the MobileAppsVELibrary project
    I have copy the libDVL.so files into AgentryAndroidClientSolition libs folder from the file SAP3DVisualEnterpriseApplicationsSDKv2_1.zip

  • SP3 and PC\IOS\Android clients.

    Hello
    Som after implementing sp3 for MDocs I cannot use PC. iOS and Android clients. Web interface works fine.
    Logs from android (same for iOS):
    2014-12-10 14:31:32.878 TRACE ApacheClientHttpInvoker: GET https://server/mcm/json/mydocuments/root?objectId=100900e4-6e1c-3110-3d83-8e6180a988da&cmisselector=object&filter=cmis%3AbaseTypeId%2Ccmis%3AchangeToken%2Ccmis%3AcontentStreamLength%2Ccmis%3AcontentStreamMimeType%2Ccmis%3AcreatedBy%2Ccmis%3AcreationDate%2Ccmis%3AlastModificationDate%2Ccmis%3AlastModifiedBy%2Ccmis%3Aname%2Ccmis%3AobjectId%2Ccmis%3AobjectTypeId&includeAllowableActions=true&includeRelationships=none&renditionFilter=cmis%3Anone&includePolicyIds=false&includeACL=false&succinct=true > Headers: {Date=[Wed, 10 Dec 2014 10:31:37 GMT], Server=[nginx], cache-control=[private, max-age=0], Transfer-Encoding=[chunked], Content-Type=[application/json;charset=UTF-8], content-encoding=[gzip], Connection=[keep-alive]}
    2014-12-10 14:31:32.921 DEBUG SettingsAdapter: List item at position 7 is being rendered: 2131493071
    2014-12-10 14:31:32.938 ERROR MetadataDownloadThread: Error ERROR_SESSION_EXPIRED in metadata thread processing task (repository mydocuments, Low, SyncedItemsRefresh, Folder: [100900e4-6e1c-3110-3d83-8e6180a988da])
    org.apache.chemistry.opencmis.commons.exceptions.CmisPermissionDeniedException: INVALID_TOKEN_PROVIDED
         at org.apache.chemistry.opencmis.client.bindings.spi.browser.AbstractBrowserBindingService.convertStatusCode(AbstractBrowserBindingService.java:257)
         at org.apache.chemistry.opencmis.client.bindings.spi.browser.AbstractBrowserBindingService.read(AbstractBrowserBindingService.java:361)
         at org.apache.chemistry.opencmis.client.bindings.spi.browser.ObjectServiceImpl.getObject(ObjectServiceImpl.java:278)
         at org.apache.chemistry.opencmis.client.runtime.SessionImpl.getObject(SessionImpl.java:519)
         at org.apache.chemistry.opencmis.client.runtime.SessionImpl.getObject(SessionImpl.java:497)
         at com.sap.mcm.android.util.CmisUtil.getCmisObjects(CmisUtil.java:96)
         at com.sap.mcm.android.sync.impl.SyncedItemsRefreshOperation.execute(SyncedItemsRefreshOperation.java:32)
         at com.sap.mcm.android.sync.impl.MetadataDownloadThread.run(MetadataDownloadThread.java:158)
    2014-12-10 14:31:33.071 DEBUG MetadataDownloadThread: Requeued failed task (repository mydocuments, Low, SyncedItemsRefresh, Folder: [100900e4-6e1c-3110-3d83-8e6180a988da])
    2014-12-10 14:31:33.074 DEBUG MetadataDownloadThread: Reconnecting session for repository mydocuments
    But for PC (it also is newest) client logs looks different:
    2013 23 Oct 06:42:19 [MCM Multiple Instance Listener] ERROR com.sap.mcm.util.SingleInstancePortListener  - Error while creating server socket! java.net.BindException: Address already in use: JVM_Bind at java.net.DualStackPlainSocketImpl.bind0(Native Method) at java.net.DualStackPlainSocketImpl.socketBind(DualStackPlainSocketImpl.java:96) at java.net.AbstractPlainSocketImpl.bind(AbstractPlainSocketImpl.java:376) at java.net.PlainSocketImpl.bind(PlainSocketImpl.java:175) at java.net.ServerSocket.bind(ServerSocket.java:376) at java.net.ServerSocket.(ServerSocket.java:237) at java.net.ServerSocket.(ServerSocket.java:128) at com.sap.mcm.util.SingleInstancePortListener.run(SingleInstancePortListener.java:20) 2013 23 Oct 06:42:19 [MCM Multiple Instance Listener] ERROR com.sap.mcm.util.SingleInstancePortListener  - Error while creating server socket! java.net.BindException: Address already in use: JVM_Bind at java.net.DualStackPlainSocketImpl.bind0(Native Method) at java.net.DualStackPlainSocketImpl.socketBind(DualStackPlainSocketImpl.java:96) at java.net.AbstractPlainSocketImpl.bind(AbstractPlainSocketImpl.java:376) at java.net.PlainSocketImpl.bind(PlainSocketImpl.java:175) at java.net.ServerSocket.bind(ServerSocket.java:376) at java.net.ServerSocket.(ServerSocket.java:237) at java.net.ServerSocket.(ServerSocket.java:128) at com.sap.mcm.util.SingleInstancePortListener.run(SingleInstancePortListener.java:20) 2013 23 Oct 06:42:19 [MCM Multiple Instance Listener] ERROR com.sap.mcm.util.SingleInstancePortListener  - Error while creating server socket! java.net.BindException: Address already in use: JVM_Bind at java.net.DualStackPlainSocketImpl.bind0(Native Method) at java.net.DualStackPlainSocketImpl.socketBind(DualStackPlainSocketImpl.java:96) at java.net.AbstractPlainSocketImpl.bind(AbstractPlainSocketImpl.java:376) at java.net.PlainSocketImpl.bind(PlainSocketImpl.java:175) at java.net.ServerSocket.bind(ServerSocket.java:376) at java.net.ServerSocket.(ServerSocket.java:237) at java.net.ServerSocket.(ServerSocket.java:128) at com.sap.mcm.util.SingleInstancePortListener.run(SingleInstancePortListener.java:20) 2013 23 Oct 06:42:41 [Thread-0] ERROR com.sap.mcm.util.Setup  -
    Client already running!
    But of course I checked and it is not running twice... Thanks for helping.

    Hi, It will be better if you open a OSS ticket for this.

  • Anyway for client to use JES IM without downloading software?

    Is there anyway for a client to use JES IM without downloading software. If I kick off IM using the JAVA web start method, it tries to download over 5M of software. What does the Java Plug-In method do? The documentation seems to imply that it only works on Windows and it also downloads software. I have clients that do not allow software downloads from the Internet.

    Its only a onetime download of IM Client jars, anyways if you don't want to download any software & want to access IM, you can use any browser-based XMPP client . A good one ir http://jwchat.sourceforge.net/. You can access IM features using this web-client through browser. But this is an open-source client & doesn't support all the features our IM server supports.
    Note: This client will only work with 2006Q1 release of Sun Java System Instant Messaging Server. You need to use httpbind feature of this release to access XMPP based IM services through browser. For more on httpbind check this out : http://docs.sun.com/app/docs/doc/819-2503/6n4po7r1q?a=view
    HTH

  • Music streaming from an Android client application through Apple Express?

    Does anyone know of an Android client application that streams music to powered speakers via Airplay through an Apple Express?

    You would not need to stream from MacBook to iPad to Apple TV.
    You can use the iPad iTunes Remote to control the MacBook iTunes to stream to the AppleTV2.
    FYI: AirPlay does not work with 1st gen AppleTV.

  • Lync 2013 Android Client and simultaneous ring problem

    this is sort of a duplicate but since the other one was marked as answered when it was not I figured I'd start this topic up again.
    I set up the Android mobile client on my phone and all seemed to work fine (apart from the know bu where it keeps saying "calls aren't setup to ring mobile device..."  whether the are or not) but I've run into the super annoying issue where
    even if you turn simultaneous ring off for the cell phone number it still rings through when I get a call on my Lync work phone (a bit delayed so it rings just before voice mail picks up). What stinks is that even if I completely sign out of the Lync mobile
    app I still get these ring throughs. The only solution was to reinstall the app with a bogus cell number (which is a bad way to go as it might be calling a random number if I'm not careful). the other thread had a moderator give the answer to create a user
    level voice policy to not allow simultaneous ringing. Yeah, thanks. I'd actually like to use the feature sometimes and so would all of my users.
    So, is this a bug in the Android client? In the Mobile functionality on the server? What? When I run SEFAUtil on my account it doesn't show any simulring or forwarding (my full Lync 2013 client agrees with that) so what the heck is going on. I can't roll
    this upgrade from 2010 out to users until this can be resolved.
    Steve

    I think I found the solution to the annoying ring to the phone even when your turn off your call forwarding/sim ring.
    In Lync 2013 desktop client, when you first setup SIM ring, it asks you to enter the phone that you would like to have sim ring. In this case, most likely your cellphone number. Then when you are sick of SIM ring, you decide to turn this feature off, but
    you still get SIM ring to your cellphone which is very annoying. If I remember correctly, in Lync 2010, when you switch from SIM ring ON to OFF, the cellphone number will be deleted automatically. In Lync 2013, however, doesn't do so. Therefore, your cellphone
    number is still there even though your have call forwarding OFF. This is a bug. The work around to it is to go to Tools > Options > Call Forwarding, select SiM ring; then from the drop down list, instead of choosing your saved cellphone number, choose
    WORK number. Then select "Turn Off Call Forwarding". Now, go back to SIM ring option again, you will see the saved cellphone number is now gone. It will only display your work number. Now, try to make a test call to your Lync phone, it shouldn't ring to your
    cellphone anymore.
    To me, this seems to have fixed it. You can try this and let me know if that fixes yours too.
    A@RJC

  • Lync 2013 android client fails to login bug when ISP overrides DNS

    Hello all,
    I've noticed an issue occurring in the latest Android client (as of 3/9/2015) with internet networks where the provider resolves all DNS queries to an IP address (e.g. T-Mobile, Cox Cable, and lots of others).
    Essentially, sometimes I have noticed my android client stuck on "Signing in".  The diagnostic logs show that the client is attempting to resolve http://lyncdiscover.contoso.com (which is not resolvable
    externally), but T-Mobile is sending it into a search engine.  The app continues to try to connect despite not realizing that it really did not resolve properly.  See below logs.
    <html><head><meta http-equiv="refresh" content="0;url=http://lookup.t-mobile.com/index.php?origURL=http://lyncdiscoverinternal.contoso.com/"/></head><body><script type="text/javascript">window.location="http://lookup.t-mobile.com/index.php?origURL="+escape(window.location)+"&r="+escape(document.referrer);</script></body></html>
    </ReceivedResponse>
    Mar 9, 2015 8:26:50 AM ERROR LYNC: ERROR TRANSPORT /Volumes/ServerHD2/buildagent/workspace/200604/tps/ucmp/ucmp/transport/common/private/TransportUtilityFunctions.cpp/1874:Accept-types (application/vnd.microsoft.rtc.autodiscover+xml;v=1) not found in Content-Type response from server (text/html). Not decoding.
    Mar 9, 2015 8:26:50 AM INFO LYNC: INFO TRANSPORT /Volumes/ServerHD2/buildagent/workspace/200604/tps/ucmp/ucmp/transport/requestprocessor/private/CHttpRequestProcessor.cpp/266:Sending event to main thread for request(0x9a306048)
    Mar 9, 2015 8:26:50 AM INFO LYNC: INFO APPLICATION /Volumes/ServerHD2/buildagent/workspace/200604/tps/ucmp/ucmp/applicationlayer/infrastructure/private/CTransportRequestRetrialQueue.cpp/822:Req. completed, Stopping timer.
    Mar 9, 2015 8:26:50 AM INFO LYNC: INFO APPLICATION /Volumes/ServerHD2/buildagent/workspace/200604/tps/ucmp/ucmp/applicationlayer/infrastructure/private/CUrlRedirectAndTrustResolver.cpp/610:UrlRedirectAndTrustResolver complete with url = http://lyncdiscoverinternal.contoso.com/, Hops = 1, status = E_ResponseUnknown (E2-1-5)
    Mar 9, 2015 8:26:50 AM INFO LYNC: INFO APPLICATION /Volumes/ServerHD2/buildagent/workspace/200604/tps/ucmp/ucmp/applicationlayer/infrastructure/private/CTransportRequestRetrialQueue.cpp/725:Response received for req. UrlTrustResolver(0x9a306048): E_ResponseUnknown (E2-1-5) (RemoteNetworkPermanentError); Done with req.; Stopping resend timer
    Mar 9, 2015 8:26:50 AM INFO LYNC: INFO APPLICATION /Volumes/ServerHD2/buildagent/workspace/200604/tps/ucmp/ucmp/applicationlayer/infrastructure/private/CUcwaAutoDiscoveryGetUserUrlOperation.cpp/393:CUcwaAutoDiscoverGetUserUrlOperation::onEvent received. Status = E_ResponseUnknown (E2-1-5), url = http://lyncdiscoverinternal.contoso.com/
    Mar 9, 2015 8:26:50 AM INFO LYNC: INFO APPLICATION /Volumes/ServerHD2/buildagent/workspace/200604/tps/ucmp/ucmp/applicationlayer/infrastructure/private/CUcwaAutoDiscoveryGetUserUrlOperation.cpp/224:UcwaAutoDiscoveryGetUserUrlOperation completed with url = http://lyncdiscoverinternal.contoso.com/?sipuri=sip:[email protected], userUrl = , status = E_ResponseUnknown (E2-1-5)
    Mar 9, 2015 8:26:50 AM DEBUG SigningInActivity: onStop()
    Mar 9, 2015 8:26:50 AM DEBUG SigninActivity: onStop()
    Mar 9, 2015 8:27:20 AM DEBUG HubActivity: onPause()
    Mar 9, 2015 8:27:20 AM DEBUG MyStatusFragment: onPause()
    Mar 9, 2015 8:27:20 AM DEBUG ContactsFragment: onPause()
    Mar 9, 2015 8:27:20 AM DEBUG HubActivity: onStop()
    Mar 9, 2015 8:27:20 AM INFO LYNC: INFO APPLICATION /Volumes/ServerHD2/buildagent/workspace/200604/tps/ucmp/ucmp/applicationlayer/objectmodel/private/CApplication.cpp/944:CApplication::serialize() called
    Mar 9, 2015 8:27:20 AM VERBOSE LYNC: VERBOSE APPLICATION /Volumes/ServerHD2/buildagent/workspace/200604/tps/ucmp/ucmp/applicationlayer/infrastructure/privateandroid/CCredentialStore.cpp/90:storing credentials for service:0
    Mar 9, 2015 8:27:20 AM VERBOSE LYNC: VERBOSE APPLICATION /Volumes/ServerHD2/buildagent/workspace/200604/tps/ucmp/ucmp/applicationlayer/infrastructure/privateandroid/CCredentialStore.cpp/90:storing credentials for service:1
    Mar 9, 2015 8:27:20 AM INFO LYNC: INFO APPLICATION /Volumes/ServerHD2/buildagent/workspace/200604/tps/ucmp/ucmp/applicationlayer/objectmodel/private/CBasePersistableEntity.cpp/179:Storing 1 out-of-sync Object Models took 32ms
    Mar 9, 2015 8:27:20 AM INFO LYNC: INFO UTILITIES /Volumes/ServerHD2/buildagent/workspace/200604/tps/ucmp/platform/persistentstorage/private/CBasePersistableComponent.cpp/245:Storing 3 out-of-sync components took 1ms
    Mar 9, 2015 8:27:20 AM INFO PreferencesManager: commit is called on
    Mar 9, 2015 8:27:20 AM DEBUG MyStatusFragment: onStop()
    Mar 9, 2015 8:27:20 AM DEBUG ContactsFragment: onStop()
    Mar 9, 2015 8:27:27 AM ERROR HttpConnection: org.apache.http.conn.HttpHostConnectException: Connection to https://lyncdiscoverinternal.contoso.com refused
    at org.apache.http.impl.conn.DefaultClientConnectionOperator.openConnection(DefaultClientConnectionOperator.java:183)
    at org.apache.http.impl.conn.AbstractPoolEntry.open(AbstractPoolEntry.java:164)
    at org.apache.http.impl.conn.AbstractPooledConnAdapter.open(AbstractPooledConnAdapter.java:119)
    at org.apache.http.impl.client.DefaultRequestDirector.execute(DefaultRequestDirector.java:360)
    at org.apache.http.impl.client.AbstractHttpClient.execute(AbstractHttpClient.java:555)
    at org.apache.http.impl.client.AbstractHttpClient.execute(AbstractHttpClient.java:487)
    at com.microsoft.office.lync.platform.http.HttpEngine.execute(HttpEngine.java:502)
    at com.microsoft.office.lync.platform.http.HttpConnection$1.run(HttpConnection.java:219)
    at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:422)
    at java.util.concurrent.FutureTask.run(FutureTask.java:237)
    at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1112)
    at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:587)
    at java.lang.Thread.run(Thread.java:818)
    Caused by: java.net.ConnectException: failed to connect to /198.105.244.104 (port 443) after 180000ms: isConnected failed: ECONNREFUSED (Connection refused)
    at libcore.io.IoBridge.isConnected(IoBridge.java:238)
    at libcore.io.IoBridge.connectErrno(IoBridge.java:171)
    at libcore.io.IoBridge.connect(IoBridge.java:122)
    at java.net.PlainSocketImpl.connect(PlainSocketImpl.java:183)
    at java.net.PlainSocketImpl.connect(PlainSocketImpl.java:456)
    at java.net.Socket.connect(Socket.java:882)
    at org.apache.http.conn.scheme.PlainSocketFactory.connectSocket(PlainSocketFactory.java:119)
    at org.apache.http.impl.conn.DefaultClientConnectionOperator.openConnection(DefaultClientConnectionOperator.java:144)
    ... 12 more
    Caused by: android.system.ErrnoException: isConnected failed: ECONNREFUSED (Connection refused)
    at libcore.io.IoBridge.isConnected(IoBridge.java:223)
    ... 19 more
    Since DNS overrides by ISPs are a common occurance, I believe the app should properly handle this situation.  I installed an app to override my DNS and use Google's DNS servers, and the client connects fine.

    Hi,
    Did you login Lync 2013 mobile client internal or external the company?
    Did the issue also happen for IOS/Windows Phones or just happen for Android Phones?
    Please try to check if the issue only happen for your mobile Lync client or also happen for other Android mobile clients.
    If the issue only happen for your Android mobile, please try to uninstall Lync client and install the latest version from Android Market and test the issue again.
    If the issue happen for multiple mobile clients, please double check the Reverse Proxy settings, if you use IIS ARR for Reverse Proxy, you can troubleshooting with the help of the link below:
    http://blogs.technet.com/b/nexthop/archive/2013/02/19/using-iis-arr-as-a-reverse-proxy-for-lync-server-2013.aspx
    Best Regards,
    Eason Huang
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected].
    Eason Huang
    TechNet Community Support
    Ok, I figured out that I had a partial misconfiguration, but the existing client behavior still leads to long delays on a variety of networks.  I had the reverse proxy forwarding into port 80 instead of 8080, which seemingly caused problems
    during the second autodiscovery phase after the first timed out.   I have since confirmed that it's not just T-Mobile, but any such provider (e.g. Cox Cable, see below) that resolves all DNS entries.
    Essentially, the following is happening:
    1) Client attempts to resolve lyncdiscoverinternal first.
    2) DNS record resolves to ISP's website, because they resolve everything and will return their own page if the entry really doesn't exist.
    3) Lync client continues to try to connect to the ISP's address, and sits for at least a minute until it eventually falls to the lyncdiscover record.
    From the below log entries, you can see that the login process is delayed a full minute due to the client being stuck on the lyncdiscoverinternal record!  Again, this does not occur on ISPs that do not catch all DNS resolution
    attempts, regardless of validity.
    Mar 9, 2015 8:10:04 PM INFO HttpConnection: originalurl is
    https://lyncdiscoverinternal.contoso.com/?sipuri=sip:[email protected] method Get
    Mar 9, 2015 8:10:04 PM INFO HttpConnection: decodedurl is
    https://lyncdiscoverinternal.contoso.com/?sipuri=sip:[email protected]
    Mar 9, 2015 8:10:04 PM INFO LYNC: INFO TRANSPORT /Volumes/ServerHD2/buildagent/workspace/200604/tps/ucmp/ucmp/transport/common/private/TransportUtilityFunctions.cpp/689:<SentRequest>
    GET
    https://lyncdiscoverinternal.contoso.com/?sipuri=sip:[email protected] 9, 2015 8:10:05 PM INFO LYNC: INFO APPLICATION /Volumes/ServerHD2/buildagent/workspace/200604/tps/ucmp/ucmp/applicationlayer/infrastructure/private/CUcwaAutoDiscoveryGetUserUrlOperation.cpp/224:UcwaAutoDiscoveryGetUserUrlOperation
    completed with url =
    http://lyncdiscoverinternal.contoso.com/?sipuri=sip:[email protected], userUrl = , status = E_ResponseUnknown (E2-1-5)
    GET http://lyncdiscoverinternal.contoso.com/
    <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "<html><head><meta">http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html><head><meta
    http-equiv="refresh" content="0;url=http://finder.cox.net/main?InterceptSource=0&ClientLocation=us&ParticipantID=96e687opkbv4scrood8k84drs6gw5duf&FailureMode=1&SearchQuery=&FailedURI=http%3A%2F%2Flyncdiscoverinternal.contoso.com%2F&AddInType=4&Version=2.1.8-1.90base&Referer=&Implementation=0&method=GET"/><script
    type="text/javascript">url="http://finder.cox.net/main?InterceptSource=0&ClientLocation=us&ParticipantID=96e687opkbv4scrood8k84drs6gw5duf&FailureMode=1&SearchQuery=&FailedURI=http%3A%2F%2Flyncdiscoverinternal.contoso.com%2F&AddInType=4&Version=2.1.8-1.90base&Referer=&Implementation=0&method=GET";if(top.location!=location){var
    w=window,d=document,e=d.documentElement,b=d.body,x=w.innerWidth||e.clientWidth||b.clientWidth,y=w.innerHeight||e.clientHeight||b.clientHeight;url+="&w="+x+"&h="+y;}window.location.replace(url);</script></head><body></body></html>
    </ReceivedResponse>
    Mar 9, 2015 8:10:21 PM INFO LYNC: INFO APPLICATION /Volumes/ServerHD2/buildagent/workspace/200604/tps/ucmp/ucmp/applicationlayer/infrastructure/private/CUcwaDataSynchronizer.cpp/799:Mode 0
    timed out
    Mar 9, 2015 8:11:08 PM ERROR HttpConnection: org.apache.http.conn.HttpHostConnectException:
    Connection to https://lyncdiscoverinternal.contoso.com refused
     at org.apache.http.impl.conn.DefaultClientConnectionOperator.openConnection(DefaultClientConnectionOperator.java:183)
    Mar 9, 2015 8:11:08 PM INFO LYNC: INFO TRANSPORT /Volumes/ServerHD2/buildagent/workspace/200604/tps/ucmp/ucmp/transport/common/private/TransportUtilityFunctions.cpp/1032:<ReceivedResponse>
    GET http://lyncdiscover.contoso.com/

  • Develop SAP CRM Android Client

    Hi All,
    I want to create an Android app for SAP CRM, but I am not able to find from where to get free CRM trial account and API details.
    I found this link http://www.sap.com/pc/tech/cloud/software/cloud-for-sales/free-trial.html  for free cloud account but no API definition given for same, is there any other way to create free demo account for SAP CRM.
    Thanks in Advance.
    PS:
    I installed GWPA plugin, and able to communicate with already hosted services (http://scn.sap.com/docs/DOC-31221) on SAP cloud via android client.

    Hello
    Yes It was an issue in 7.0 SP 01 release.It is fixed from 7.0 SP 04 Mobile release. To avoid the MAS Help installation, Please follow the below steps.
    1. In the 7.0 SP 01 DVD Structure, A  file called 'config.xml' which is available at 'Mobile_Client_Installation' folder.
    2. Take the backup for this file. Open the XML file, Remove the following entry.
    <MsiTask TaskName="MASHelpTask" ProductCode="{AE558035-159C-4621-A6A2-E34CCFD6639D}" RelativePath="..\SAP Mobile Application Studio Help Integration\SAP MAS Help.msi" SetupMode="Install" UIMode="BasicUI" TaskType="MSI" PendingTitle="SAP MAS Help is yet to be installed" RunningTitle="Installing SAP MAS Help" SuccessTitle="SAP MAS Help installed successfully" FailureTitle="Installation of SAP MAS Help failed" FailOnExit="true" IfDefined="MSDNFOUND" LogSetup="true" VerboseLog="true" LogPrefix="MASHelp" />
    3. Now start the installation. It shd work.
    Regards
    Shankar

  • How can I transfer photos from an android based phone to my iPad without going thru my PC?

    How can I transfer pictures from my android based phone to my iPad without going through my PC?

    I like to get my media shared in the cloud so its reachable across all my devices.
    Dropbox, Box and Google Drive will be your friend.

Maybe you are looking for