Certificate problem in Proxy Server (ODSEE 11g)
I am having a problem adding a CA Certificate to the Proxy Server. I followed the steps in the documentation, however I get the error: "keytool error: java.lang.Exception: Public keys in reply and keystore don't match".
From what I have read, this error means that the alias name I am using when I add the new certificate is already being used. As per the documentation...
When you request a CA-signed certificate, a temporary self-signed certificate is created. When you receive and install the CA-signed certificate from the CA, the new certificate replaces the temporary self-signed certificate.
... and this does happen. However when I bring in the new cert to replace... I get the mentioned error.
If I use a different alias, it doesn't give me an error. However, I can't see it when I use the "dpadm list-certs" command (although it is there when I use the keytool command). More importantly, the "defaultservercert" is still the certificate being used when accessing the server.
So the big question is... How do I get the Proxy Server to use the new CA Certificate?
I've tried using the keytool command in many different ways, and it fails each time. Lesson learned: don't mess with the keystore via keytool. Any changes made are not recognized by the Proxy Server.
I don't have access to this Proxy Server via DSCC because I do not have the password for the account running the services (a restriction made by the client), so it all to be done via CLI.
The operating system is Oracle Solaris 10 8/11 s10s_u10wos_17b SPARC.
Here are some outputs:
$ ./dsee7/bin/dpadm list-certs ./dsee7/instances/PROXY01
Alias Valid from Expires on Self-signed? Issued by Issued to
defaultservercert 2012/06/18 09:23 2014/06/18 09:23 y CN=wpsun882:25389 Same as issuer
1 certificate found.
$ ./dsee7/bin/dpadm request-cert name devB2ADIRPROXY01.domain.com org 'COMPANY INC' org-unit IT city 'Eden Prairie' state Minnesota country US --keysize 2048 -o ./dsee7/ca-cert.csr ./instances/PROXY01 ca-cert
$ ./dsee7/bin/dpadm list-certs ./dsee7/instances/PROXY01
Alias Valid from Expires on Self-signed? Issued by Issued to
defaultservercert 2012/06/18 09:23 2014/06/18 09:23 y CN=wpsun882:25389 Same as issuer
ca-cert 2012/06/18 09:25 2014/06/18 09:25 y C=US, ST=Minnesota, L=Eden Prairie, O=COMPANY INC, OU=IT, CN=devB2ADIRPROXY01.domain.com Same as issuer
2 certificates found.
$ ./dsee7/bin/dpadm add-cert ./dsee7/instances/PROXY01 ca-cert ./dsee7/wpsun882.pem
keytool error: java.lang.Exception: Public keys in reply and keystore don't match
Thanks in advance!
I can elaborate it further
class GUI extends JFrame implements Runnable
public void updateGUI()
//update the GUI
class MailListener extends Thread
GUI refernce; // Reference to the GUI class
public MailListener(GUI g)
reference = g;
public void run
while(true)
//wait for a message and call the updateGUI() method of
GUI class when u get a message
}
Similar Messages
-
Hi All,
After several hours and a short night of sleep I'm out of ideas and hopefully someone here can help me trying to solve this one. First of all the situation:
Exchange 2013 on a remote location with a CA-certificate.
Outlook 2010 and 2013 on different locations, locally installed and on RDS.
When I open Outlook on my laptop all is fine, no errors, good sync, no problem. But when I open Outlook on our Remote Desktop Servers with Outlook 2013 I'm getting errors like "There is a problem with the security certificate of the proxy server. The
name on the security certificate is invalid or does not match the name of the site. Outlook is unable to connect to this server. (Error code 18)". Opening Outlook 2010 the message is the same, but the error code now is 38.
After this Outlook opens and is working, there's one more error though. After a while an security warning pops up with the message: "Information you exchange with this site cannot be viewed or changed by others. However, there is a problem with the
site's security certificate. * The security certificate was issued by a company you have not chosen to trust. View the certificate to determine whether you want to trust the certifying authority. * The security certificate is valid. * The name on the security
certificate is invalid or does not match the name of the site."
Strangest thing is, it is the certificate of my RDS! It isn't my valid en officially bought certificate from my mailserver. What's going on? I'm out of options, what I've tried so far (in random order):
- restarting mailserver and AD;
- restarting switches;
- restarting routers;
- restarting RDS, AD and all other servers;
- bypassed proxyserver for RDS;
- created a new profile;
- checked recently installed updates;
- checked certificate on mailserver;
- checked RDS on a different location, working fine.
Nothing helped, what can I do next? Please advice.
Regards.Found a thread that solves half my problem (https://social.technet.microsoft.com/Forums/office/en-US/70d18244-889a-4d95-ac3f-e234672a82b2/there-is-a-problem-with-the-proxy-servers-security-certificate-error-when-starting-outlook?forum=exchangesvrclients).
The first message can be suppressed by adding this to the Exchange config:
set-outlookprovider -Identity EXCH -CertprincipalName msstd:webmail.domain.tld
set-outlookprovider -Identity EXPR -CertprincipalName msstd:webmail.domain.tld
Giving the command get-outlookprovider, gives me empty information regarding the certprinipalname. Filled
this and after recreating the profile or deleting the ost-file I still have the second alert with the local certificate of my RDS.
Not completely where I want to be, any help regarding the second alert is greatly appreciated! -
Communication problem with proxy server
We have establish the configuration of an iPad to access the enterprise net, but when trying to access any webpage we get the next message: Safari can not open the page. Error:"There is a communication problem with proxy web server (HTTP)"
The access has no problems with other movile devices.
Ahy help?Hi,
I am not sure whether you have already solved the problem or not....
Do the following to deploy MobileBIService.war file on tomcat
1.Stop Tomcat Web application server.
2.Copy the file, MobileBIService.war from [Install directory]\Mobile 14\Client to the Tomcat's "Webapps" directory.
In my case, I copied the MobileBIService.war from C:\Program Files (x86)\SAP BusinessObjects\Mobile14\Client to C:\Program Files (x86)\SAP BusinessObjects\Tomcat6\webapps. ( I used BO 4.0 SP02)
3. Start Tomcat.
Restarting Tomcat would automatically deploy war file as a Web App
One folder u201CMobileBiServiceu201D will appear in webapps folder when MobileBIService.war is deployed successfully.
Hope it helps.
Regards,
Ankur -
Proxy Problem The proxy server is refusing connections
I run Windows XP. I did have a Cybot backdoor Activity attack intercepted by Norton Internet Security and I used the Norton NPE to remove it from the computer. I do not know if this caused the proxy problem or not.
There is no proxy problem connecting to the internet through Internet Explorer just through Mozilla Firefox.
When Mozilla Firefox tries to connect to the internet I get the following message:
Firefox is configured to use a proxy server that is refusing connections.
Check the proxy settings to make sure that they are correct.
Contact your network administrator to make sure the proxy server is
working.
In Mozilla I click Tools, options, advanced, network, settings. Under settings Proxy is set on manual, it says that there is no proxy for the figures typed in.
So I click auto detect proxy and I then can connect to internet through Mozilla, however when I log out of the internet, the same proxy server issue is recreated.
What should the Proxy setting be?You can find the connection settings in Tools > Options > Advanced : Network : Connection
If you do not need to use a proxy to connect to internet then select "No Proxy"
See "Firefox connection settings":
* https://support.mozilla.com/kb/Firefox+cannot+load+websites+but+other+programs+can
Start Firefox in <u>[[Safe Mode]]</u> to check if one of the extensions is causing the problem (switch to the DEFAULT theme: Firefox (Tools) > Add-ons > Appearance/Themes).
*Don't make any changes on the Safe mode start window.
*https://support.mozilla.com/kb/Safe+Mode
*https://support.mozilla.com/kb/Troubleshooting+extensions+and+themes
See also:
*http://kb.mozillazine.org/Preferences_not_saved -
Problem: hidden proxy server?
Need help with this email I just received on my .MAC account - what does it mean? Should I just ignore it, delete the message, or is there something I should be checking to prevent it from happening again? I have NOT downloaded the attachment.
Thank you. DJ
Received the following message:
FROM: returned mail <[email protected]>
SUBJECT: Returned mail: Data format error
1 attachment, 31.4 KB
Dear user [email protected],
We have detected that your account has been used to send a large amount of spam messages during the recent week.
Most likely your computer was compromised and now runs a hidden proxy server.
We recommend you to follow the instructions in the attachment in order to keep your computer safe.
Best regards,
The mac.com team.
mac.com.zip (31.4 KB)
IMac G5 17" Mac OS X (10.4.8) safari and firefox browsersIgnore it, it’s junk. Most likely the attachment contains a virus meant to be run on Windows.
-
Server 2012 Patch and Certificate Problems - GPO Breaking Server
We built some Server 2012 R2 servers, the first ones in our organization. We were able to install SQL 2012 with no issues. We are required by organization policy to harden our computers. But when tried to install WSUS patches we began noticing several problems...messages
like "the signer of the message is invalid or not found (0x8006002)" and "revocation process could not continue - the certificate(s) could not be checked) (0x800B010E and in event viewer 2148204814). We can only run Internet Explorer if we go
to an admin command prompt, change to "program files\internet explorer" and type "iexplore.exe". Obviously we can not make these servers live until this problem is fixed. Two of us have spent two weeks on this. We can join a hardened
Server 2012 R2 image to the domain and things still work. The point that it breaks at is when we apply our default domain GPO. It doesn't matter if we apply other GPOs singly or en masse, it's the default one that is breaking it. If we unapply the default GPO,
it's still broken, so it's something that is not undone by removing the GPO. So while the breaking GPO is known, nothing we have tried has enabled us to narrow down what in the GPO is breaking this. We compared RSOPs on a working and non working image and
they are the same.
Something else worth noting is that the default domain GPO does not break our 2003 or 2008 servers. So the offending setting affects Server 2012 differently.
Any ideas on what this setting might be or how to narrow the plethora of settings in our GPO?
This build has IE 11. IE64 works in metro mode but both IE64 and 32 don't work in desktop mode.
WSUS says certs for wuident.cab are not found but we've manually loaded them into the local store.
As a side note, Server 2012 needs to have access to another CRL list in addition to what prior versions of Windows Server needs, towit: http;//www.microsoft.com/pkiops/crl
Any help would be greatly appreciated.
Ben JohnsonWYHi Ben,
>>IE is still not working right. Still working that one
Based on your description, were there any related error event id logged? What’s the message when we opened IE normally?
For this involves IE and for better help, we can also ask for advice in the following forum.
Internet Explorer 8, 9, 10, 11 Preview
http://social.technet.microsoft.com/Forums/ie/en-US/home?forum=ieitprocurrentver
Best regards,
Frank Shen -
Outlook 2013: There is a problem with the proxy server's certificate
Hello!
One more question regarding Outlook 2013/Exchange2013SP1:
There are three lab PCs: DC, Exch1, Exchange2. There's a wildcard certificate installed on Exch1 (https://social.technet.microsoft.com/Forums/en-US/6a440c99-47bd-4f48-8cc5-9f92e6b06496/wildcard-certificate-for-exchange-2013?forum=exchangesvrgeneral).
OWA works perfect with this wildcard certificate.
I install Outlook2013 on Exch1 and get the error:
DC.Entreprise.Local is a computer certificate issued for the computer DC.Enterprise.Local.
DC.Enterprise.Local IS NOT (and never was) the proxy for Exch1 or Exchange2:
How Outlook could request DC's certificate if the proxy server = Exch1.Enterprise.Local???
Thank you in advance,
MichaelHello all,
Thank you for your replies!
Since I'm using a wildcard certificate I changed Outlook providers according to this:
http://blogs.technet.com/b/exchange/archive/2013/08/02/part-2-reverse-proxy-for-exchange-server-2013-using-iis-arr.aspx
If you do choose to use a wildcard certificate, you should also make sure that you
change the EXPR Outlook Provider, so that Outlook Anywhere clients can successfully connect to the Exchange Server (this behavior can be a particular issue
if you have Windows XP clients). If you do not make this change then end users may continue to receive a prompt for a certificate mismatch."
...and EXCH and EXPR are both set to *.Enterprise.Local.
"I install Outlook2013 on Exch1" you mean you install Outlook on top of Exchange?" - on the same server as Exchange, and in this case Outlook must use SCP, not DNS (the server and the client are in the same AD domain).
"Without SCP, Exchange try DNS autodiscover lookup, first site it will try is
https://emaldomain/autodiscover/autodiscover.xml, which happen to be resolve to your domain controller." - I think that's the case... I just don't understand why
an internal client can't find the SCP that does exist and point to exch1.enterprise.local:
Regards,
Michael -
Unable to make SSL connection from Proxy Server to Directory Server
I have recently installed Directory Proxy Server 5.2 Patch 3 on Solaris 9 server. Backend directories are Sun Directory Server 5.2sp3 using Thawte signed certificates.
I can't get the Proxy Server to make a successful SSL connection to the Directory Servers. The proxy server can make the non-ssl connection without problem. When the Proxy Server attempts the SSL connection it gives SEC_ERROR_UNTRUSTED_ISSUER error. The SSL certificates on the Directory Servers are signed by Thawte and have just recently been updated. The certificate for the Proxy Server is also signed by Thawte. The CA certificate is loaded in both the Proxy Server and the Directory Server.
I also have an iPlanet Directory Access Router (iDAR) 5.0 Server that is our current production server that serves these same directories and I haven't had a problem with SSL connection with it. So, the certificates are good.
I've encluded an exerpt from the Proxy Server log below for one of SSL connection attempts.
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [STAT/CONN] [ 560
307] Connection from secured listen port. New connection is on socket 37.
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [STAT/CONN] [ 560
305] Number of open connections is 1.
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [STAT/CONN] [ 171
211] [client( 152.3.100.30, 37)] Accepting connection via dukenet-group
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 302
023] Failure with CERT_VerifyCertNow (checking signature, usage: "certUsageSSLSe
rver").
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 302
023] SEC_ERROR_BASE + 20, NSPR error: -8172 (0xffffe014). Native errno is: 11
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 385
729] Rejected certificate on socket 38
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 385
729] SEC_ERROR_BASE + 20, NSPR error: -8172 (0xffffe014). Native errno is: 11
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 385
728] Certificate rejected on socket 38
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 385
728] SEC_ERROR_BASE + 20, NSPR error: -8172 (0xffffe014). Native errno is: 11
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 385
721] Read on socket 38 failed.
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 385
721] SEC_ERROR_BASE + 20, NSPR error: -8172 (0xffffe014). Native errno is: 11
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [EXCEPTION] [ 301
006] Unexpected error on socket 38. (Error: -8172).
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 171
002] [client( 152.3.100.30, 37)] [server( 152.3.101.110+ 636, 38)] L
ost connection to server, trying to failover to another
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 302
023] Failure with CERT_VerifyCertNow (checking signature, usage: "certUsageSSLSe
rver").
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 302
023] SEC_ERROR_BASE + 20, NSPR error: -8172 (0xffffe014). Native errno is: 11
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 385
729] Rejected certificate on socket 38
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 385
729] SEC_ERROR_BASE + 20, NSPR error: -8172 (0xffffe014). Native errno is: 11
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 385
728] Certificate rejected on socket 38
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 385
728] SEC_ERROR_BASE + 20, NSPR error: -8172 (0xffffe014). Native errno is: 11
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [EXCEPTION] [ 385
717] ber_flush unexpected error on socket 38
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [EXCEPTION] [ 385
717] SEC_ERROR_BASE + 20, NSPR error: -8172 (0xffffe014). Native errno is: 11
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [EXCEPTION] [ 385
717] ber_flush unexpected error on socket 38
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [EXCEPTION] [ 385
717] NSPR error: -5938 (0xffffe8ce). Native errno is: 11
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 385
721] Read on socket 38 failed.
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 385
721] NSPR error: -5938 (0xffffe8ce). Native errno is: 11
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [EXCEPTION] [ 301
006] Unexpected error on socket 38. (Error: -5938).
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [NOTICE] [ 171
002] [client( 152.3.100.30, 37)] [server( 152.3.232.3+ 636, 38)] L
ost connection to server, trying to failover to another
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [EXCEPTION] [ 385
717] ber_flush unexpected error on socket 38
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [EXCEPTION] [ 385
717] NSPR error: -5938 (0xffffe8ce). Native errno is: 11
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [EXCEPTION] [ 190
102] [client( 152.3.100.30, 37)] Rejecting request The server is tempor
arily busy
Aug 30 2005 16:12:12 king.oit.duke.edu SunONEDPS[ 17471]: [OP/CONN] [ 170
904] [client( 152.3.100.30, 37)] [server( 152.3.101.110+ 636, 38)] C
onnection unbound by clientNo, that was on 5.1. For 6.0, my classpath has just:
%JAVA_HOME%\lib\tools.jar;%WL_HOME%\lib\weblogic_sp.jar;%WL_HOME%\lib\weblogic.jar;
%CLASSPATH%
This works fine. -
Self Signed Certificate for Web Proxy 4.0.2
Does anyone have instructions on how to create and install self signed Certificate for Web Proxy Server 4.0.2? My OS is RHEL 4.
Shed.Unfortunately you will not be able to do that from the GUI.
You will have to use certutil frin proxy-install/bin/proxy/admin/bin/certutil
Make sure that your LD_LIBRARY_PATH includes proxy-install/bin/proxy/lib
(start -shell will give you a shell with all necessary paths set.)
create a file called password-file which contains your password to your cert database
your cert database resides in the alias directory of proxy installation.
certutil -S -s "CN=My Issuer" -n myissuer -x -t "C,C,C" -1 -2 -5 -m 1234
-f password-file -d certdir -
Self Signed Certificate Problems
I admit little knowledge of certificates and just need to get one installed to test the Web Proxy Server functionality.
I followed the procedures here first
http://www.redhat.com/docs/manuals/linux/RHL-9-Manual/custom-guide/s1-secureserver-selfsigned.html
And then tried to reuse this certificate for Web Proxy Server Version: 4.0.5 B04/18/2007 11:01
I received the following error:
Incorrect usage no private key. The server could not find the private key associated with this certificate.
I assume that this is because the keypair for this certificate is not in the certificate database I first created.
I then tried to follow the instructions here:
http://forum.java.sun.com/thread.jspa?threadID=5092677
but got an IO error. not sure why.
Would anyone know how I can either get Web Proxy Server to generate its own certificate or accept the one I generated using openssl?
I appreciate any ideas or insights.
Thanks,
SeanDear Sean,
From the "Request Certificate" page create a csr. You will get a string like this.
-----BEGIN NEW CERTIFICATE REQUEST-----
MIICtDCCAZwCAQAwbzELMAkGA1UEBhMCSU4xEjAQBgNVBAgTCWthcm5hdGFrYTES
ilrOO4an8WzQ2SfPl8ZleScPoIjhBbRkwOfweQVnmFkJIBYeHHuTPTC2U0pkZU0u
jCXt6mWJmt0Pe6GAcZ4SAj9AFzvtVm52DF9zvdnywU7WjjLxR7xCo2Hws6iiPCmc
DDG8hxd77ayzNg1spI6YjrJJ6kXWWGBM
-----END NEW CERTIFICATE REQUEST-----
save this in a file say csr.file for openssl cert generation.
run this openssl command:
openssl ca -in csr.file -out yourcert.pem
Install yourcert.pem. It should go through. -
ODSEE 11g - DPS Directory proxy server suddenly increase load average
Hi all
Recently upgraded from directory server 5.2 to ODSEE 11g, one directory proxy configure to one master directory server and one consumer directory server.
all the three instances are in the same sparc t3 machine.
Directory proxy server alerts server load average on the machine is above 6.00 normally it is 0.66. I'm not sure what is causing the sudden burst in the load ? the traffic is normal there is no abnormal requests coming to the server. proxy performance degrades over the span of 24 hours ....and Once i restart the proxy services (dpsadm restart) all load averages comes to normal and directory proxy runs normal for the next two - three weeks. The same cycle continues ...I'm not sure what was causing the sudden load increase.
I increased the JVM heap size from 1GB to 2 GB still continue to have the problem ..did anyone else experience similar problem. How did you fix it....
Any input or advise in the right direction is much appreciated.
Thank you.server load I'm referring to "prstat command" - server load average suddenly shoot up from 0.66 to 6.00 ie) the CPU usage. Alert is from our server monitoring tool not related to directory proxy.
Clients report connections time out (etime goes from etime=0 ..2..4.....) over 24 hours i can see the etime increases and eventually the proxy server get hung and non responsive. Once I restart all the performance back to normal at-least for another two weeks.
I suspect there might be a memory leak or JVM Garbage collection issue -- any expert input how to figure this out will help.
Here is the JVM args in the proxy server "Xms2g -Xmx2g -Xmn1g -XX:SurvivorRatio=4 -XX:+UseParNewGC -XX:+UseConcMarkSweepGC"
Here is a jstat during the problem
./jstat -gcutil -t 25365 2s 30
Timestamp S0 S1 E O P YGC YGCT FGC FGCT GCT
982106.4 0.00 26.17 4.26 92.25 59.52 523 60.979 689 1002.587 1063.566
982108.4 0.00 26.17 4.40 92.25 59.52 523 60.979 689 1002.587 1063.566
982110.4 0.00 26.17 4.80 92.25 59.52 523 60.979 689 1002.587 1063.566
982112.4 0.00 26.17 5.10 92.25 59.52 523 60.979 690 1002.719 1063.698
982114.4 0.00 26.17 5.15 92.25 59.52 523 60.979 690 1002.719 1063.698
982116.4 0.00 26.17 5.32 92.25 59.52 523 60.979 691 1003.009 1063.988
982118.4 0.00 26.17 5.72 92.25 59.52 523 60.979 691 1003.009 1063.988
982120.4 0.00 26.17 5.80 92.25 59.52 523 60.979 691 1003.009 1063.988
982122.4 0.00 26.17 5.93 92.25 59.52 523 60.979 692 1003.168 1064.146
982124.4 0.00 26.17 6.03 92.25 59.52 523 60.979 692 1003.168 1064.146
982126.4 0.00 26.17 6.15 92.25 59.52 523 60.979 693 1003.481 1064.460
982128.5 0.00 26.17 6.18 92.25 59.52 523 60.979 693 1003.481 1064.460
982130.5 0.00 26.17 6.25 92.25 59.52 523 60.979 693 1003.481 1064.460
982132.5 0.00 26.17 6.29 92.25 59.52 523 60.979 694 1003.656 1064.635
982134.5 0.00 26.17 6.31 92.25 59.52 523 60.979 694 1003.656 1064.635
982136.5 0.00 26.17 6.36 92.25 59.52 523 60.979 695 1003.988 1064.967
982138.5 0.00 26.17 6.89 92.25 59.52 523 60.979 695 1003.988 1064.967
982140.5 0.00 26.17 6.99 92.25 59.52 523 60.979 695 1003.988 1064.967
982142.5 0.00 26.17 7.08 92.25 59.52 523 60.979 696 1004.187 1065.165
982144.5 0.00 26.17 7.31 92.25 59.52 523 60.979 696 1004.187 1065.165
982146.5 0.00 26.17 7.82 92.25 59.52 523 60.979 697 1004.553 1065.531
982148.5 0.00 26.17 7.92 92.25 59.52 523 60.979 697 1004.553 1065.531
982150.5 0.00 26.17 8.01 92.25 59.52 523 60.979 697 1004.553 1065.531
982152.5 0.00 26.17 8.17 92.25 59.52 523 60.979 698 1004.786 1065.764
982154.5 0.00 26.17 8.26 92.25 59.52 523 60.979 698 1004.786 1065.764
982156.5 0.00 26.17 8.38 92.25 59.52 523 60.979 699 1005.174 1066.153
982158.5 0.00 26.17 8.74 92.25 59.52 523 60.979 699 1005.174 1066.153
982160.5 0.00 26.17 8.88 92.25 59.52 523 60.979 699 1005.174 1066.153
982162.5 0.00 26.17 8.96 92.25 59.52 523 60.979 700 1005.433 1066.412
982164.5 0.00 26.17 9.09 92.25 59.52 523 60.979 700 1005.433 1066.412
jstat after the restart
./jstat -gcutil -t 10084 2s 30
Timestamp S0 S1 E O P YGC YGCT FGC FGCT GCT
40312.6 0.00 25.13 88.49 1.98 63.68 21 2.366 0 0.000 2.366
40314.6 0.00 25.13 88.58 1.98 63.68 21 2.366 0 0.000 2.366
40316.6 0.00 25.13 88.71 1.98 63.68 21 2.366 0 0.000 2.366
40318.6 0.00 25.13 88.99 1.98 63.68 21 2.366 0 0.000 2.366
40320.6 0.00 25.13 89.31 1.98 63.68 21 2.366 0 0.000 2.366
40322.6 0.00 25.13 89.36 1.98 63.68 21 2.366 0 0.000 2.366
40324.6 0.00 25.13 89.42 1.98 63.68 21 2.366 0 0.000 2.366
40326.6 0.00 25.13 89.53 1.98 63.68 21 2.366 0 0.000 2.366
40328.6 0.00 25.13 89.60 1.98 63.68 21 2.366 0 0.000 2.366
40330.6 0.00 25.13 89.72 1.98 63.68 21 2.366 0 0.000 2.366
40332.6 0.00 25.13 90.11 1.98 63.68 21 2.366 0 0.000 2.366
40334.6 0.00 25.13 90.56 1.98 63.68 21 2.366 0 0.000 2.366
40336.6 0.00 25.13 90.67 1.98 63.68 21 2.366 0 0.000 2.366
40338.6 0.00 25.13 90.75 1.98 63.68 21 2.366 0 0.000 2.366
40340.6 0.00 25.13 91.09 1.98 63.68 21 2.366 0 0.000 2.366
40342.6 0.00 25.13 91.36 1.98 63.68 21 2.366 0 0.000 2.366
40344.6 0.00 25.13 91.47 1.98 63.68 21 2.366 0 0.000 2.366
40346.6 0.00 25.13 91.53 1.98 63.68 21 2.366 0 0.000 2.366
40348.7 0.00 25.13 91.64 1.98 63.68 21 2.366 0 0.000 2.366
40350.7 0.00 25.13 91.77 1.98 63.68 21 2.366 0 0.000 2.366
40352.7 0.00 25.13 91.87 1.98 63.68 21 2.366 0 0.000 2.366
40354.7 0.00 25.13 91.95 1.98 63.68 21 2.366 0 0.000 2.366
40356.7 0.00 25.13 92.11 1.98 63.68 21 2.366 0 0.000 2.366
40358.7 0.00 25.13 92.19 1.98 63.68 21 2.366 0 0.000 2.366
40360.7 0.00 25.13 92.24 1.98 63.68 21 2.366 0 0.000 2.366
40362.7 0.00 25.13 92.85 1.98 63.68 21 2.366 0 0.000 2.366
40364.7 0.00 25.13 93.19 1.98 63.68 21 2.366 0 0.000 2.366
40366.7 0.00 25.13 93.40 1.98 63.68 21 2.366 0 0.000 2.366
40368.7 0.00 25.13 93.44 1.98 63.68 21 2.366 0 0.000 2.366
40370.7 0.00 25.13 93.47 1.98 63.68 21 2.366 0 0.000 2.366
Any one else had similar behavior. Any input to the right direction is highly appreciated.
Thanks. -
Hi all,
From time to time (at least once a day), the following message pops up on the user's screen:
"There is a problem with the proxy server's security certificate. Outlook is unable to connect to the proxy server . Error Code 80000000)."
If we click "OK" it goes away and everything continues to work although sometimes Outlook disconnects. It is quite annoying...
Any ideas?
Thank you in advanceHi,
For the security alert issue, I'd like to recommend you check the name in the alert windows, and confirm if the name is in your certificate.
Additionally, to narrow down the cause, when the Outlook client cannot connect again, I recommand you firstly check the connectivity by using Test E-mail AutoConfiguration. For more information, you can refe to the following article:
http://social.technet.microsoft.com/Forums/en-US/54bc6b17-9b60-46a4-9dad-584836d15a02/troubleshooting-and-introduction-for-exchange-20072010-autodiscover-details-about-test-email?forum=exchangesvrgeneral
Thanks,
Angela Shi
TechNet Community Support -
Good day Guys
First of all I am not an Exchange Expert, and I might be asking a very stupid question, but please bare with me. :)
While I was on leave our Mail server fell over and The company got a Specialist to help out for the time being.
We where\are on Microsoft Exchange 2007 , which Fell over, and the specialist was able to recover as much data as he could.
They then installed Exchange 2013 and tried to migrate everything from 2007 to 2013 and not everything migrated over.
But the problem is, Outlook Anywhere was enable on 2007 and worked a 100% (before the disaster)
With Exchange 2013 I get the following error message when trying to connect With Outlook 2013, using an external connection:
"There is a problem with the proxy server's security certificate. The name on the security certificate is invalid or does not match the name of the target site "Mailserver"
Outlook is unable to connect to the Proxy server. (Error Code 0)"
Has anyone had the Similar when migrating over from 2007 to 2013 or is this an Issue on IIS and nothing to do with Exchange migration?
Your assistance will be greatly appreciated.Hi,
Firstly, I would suggest we use Exchange 2013 FE as the Outlook Anywhere proxy server.
For the certificate issue, it mostly occurs because the host name that Outlook are trying to access does not match the certificate SAN. Please check with this point. If they do not match, you
can change the host name by referring to the following article:
https://support.microsoft.com/kb/940726/en-us?wa=wsignin1.0
Thanks,
Simon Wu
TechNet Community Support -
I am receiving the above message for internal Outlook 2013 users when they open Outlook. Despite this message, Outlook is fully functional. External OA users do not see this message. We are using an SRV record for our autodiscover and pointing it to the
name on the single cert we have. I've also already changed the outlookprovider record in Exchange. Any ideas?
TIA!Hi Alceryes,
According to the error message, Outlook is unable to connect to the proxy server (Error Code 10),
it seems an issue on the Certificate side.
FLAG_CERT_CN_INVALID 0x00000010
More details to see following KB:
http://support.microsoft.com/kb/923575
Would you like to tell me the reason that why you are using SRV record for Autodiscover?
I find a FAQ on Autodisocover for your reference, hope it is helpful:
https://social.technet.microsoft.com/Forums/office/en-US/54bc6b17-9b60-46a4-9dad-584836d15a02/troubleshooting-and-introduction-for-exchange-20072010-autodiscover-details-about-test-email?forum=exchangesvrgeneral
Thanks
If you have feedback for TechNet Subscriber Support, contact
[email protected]
Mavis Huang
TechNet Community Support -
Migrate certificate 3.x to Oracle iPlanet Web Proxy Server 4.0.20
Hi
I try to migrate from Sun iPlanet Web Proxy Server(SPWPS) 3.6 to Oracle iPlanet Web Proxy Server(OPWPS) 4.0.20 and I have some problem.
I have an instance in SPWPS-3.6 with SSL certificate, when I migrate it to OPWPS-4.0.20 using the admin interface, the certificate
is not migrate with this error message :
Migrating Keys and Certificates...
[Error] The password entered for the key is not valid
Assimilation failed.
But I am sure to enter the right password.
After that I manage the new instance in administration interface, and in Security Panel, there is a choice to "Migrate 3.x certificate"
I try this, but I get this error message
Incorrect Usage
The password entered is not valide
Can somebody help me to resolve this problem ?
Thanks in advance.Your proxy instance should start. The error you are seeing should only be for the admin server. Add the location of where your jvm.so is located to the LD_LIBRARY_PATH. The jvm.so is located under the JDK directory.
Maybe you are looking for
-
Remove credit card from app store
How do I remove my credit card information from my apple id. I no longer have a credit card
-
Audio tracks go out of pitch then return mysteriously
Quite a mystery: for some unusual reason I found when I booted my Intel iMac duo core and started Logic Pro 7, then played a project; the audio tracks (vocal's) were out of pitch. I adjusted them using a manual plug in and found a reasonable pitch at
-
2 x 512 MB DDR400 in FIS2R Slots 1 and 3, Performance Loss?
Hello, I'm starting to make progress with the RAM I'm using (with Mushkin's help ---and to their credit they've been very helpful over the phone). One thing I've noticed is that running 1x512 seems to run stably regardless of which of the 2 DIMMs I u
-
Thumbnails and expanded images
Am building a website in JSC for a realtor who wants to sell properties through it. I'd like to be able to have property thumbnail images, which on selection by a user, are expanded to true size and appear in a separate web page. Any pointers? Regard
-
Calling a JPanel to JInternalFrame.
Hi guys, I am building an MDI application. I Have a jButton (call NEW) to bring out the JInternalFrame(call FRAME_A) to the JDeskTopPanel(jDeskTopPane1). I have another jButton(call XX). This xx button will insert a JPanel(jPane1) into Frame_A (conta