[Error] Server replace my certificate

Suddenly, was replaced my certificate VeriSign on OS X Server and the Profile Manager didn't make tasks because the certificate was invalid.
We solved it adding again the VeriSign certificate and it worked again.
But, why the OS X Server replaced the certificate for itself? I attach the console errors.
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,000 kernel[0]: Sandbox: xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,283 sandboxd[454]: ([75332]) xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,302 sandboxd[454]: ([75332]) xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,320 sandboxd[454]: ([75332]) xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:21:57,339 sandboxd[454]: ([75332]) xscertd(75332) deny file-read-metadata /Library/Server
28/10/14 20:22:00,352 mail_cert_handler[75383]: command: "replace" certificate: /etc/certificates/CERTIFICATENAME.cert.pem with: /etc/certificates/CERTIFICATENAME.cert.pem
28/10/14 20:22:00,424 mail_cert_handler[75383]: replacing IMAP server certificate: /etc/certificates/CERTIFICATENAME.cert.pem with: /etc/certificates/CERTIFICATENAME.cert.pem
28/10/14 20:22:02,349 mail_cert_handler[75383]: replacing SMTP server certificate: /etc/certificates/CERTIFICATENAME.cert.pem with: /etc/certificates/CERTIFICATENAME.cert.pem
28/10/14 20:22:04,665 radius_cert_update.pl[75411]: Received "replace /etc/certificates/CERTIFICATENAME.cert.pem /etc/certificates/CERTIFICATENAME.cert.pem" command.
28/10/14 20:22:04,692 radius_cert_update.pl[75411]: RADIUS is not configured with /etc/certificates/CERTIFICATENAME.cert.pem, nothing to replace.

So based on what you are telling me...
- "limited knowledge when it comes to servers and cisco routers...."
- "the cisco has been up and running for a looong time without any problems"
I would not recommend you change to OS X Server as your NAT router.
To fully manage NAT on OS X Server, you need to do command-line editing for port mapping. Even with experience, I would prefer to leave that function to the router.
I've had good luck with linksys when it comes to basic routing requirements. I'm not sure what trouble you had in the past, but for me they've been very stable and great bang for the buck.
If you would like to block specific sites, for < $100 this router will provide NAT and a pretty decent set of firewall features:
<a class="jive-link-external-small" href="http://">http://www.linksys.com/servlet/Satellite?childpagename=US%2FLayo ut&packedargs=c%3DLProductC2%26cid%3D1130276636538&pagename=Linksys%2FCommon%2FVisitorWrapper
If that link doesn't work, it's model# BEFSX41
Jeff

Similar Messages

  • SChannel error- The SSL server credential's certificate does not have a private key information property attached to it.

    We have a public SSL certificate that allows for Active Directory sync with LDAPS on port 636 with our email smart host. This was working fine and suddenly stopped working and we are now getting SChannel errors Event ID 36869. There were no changes made
    to the Exchange server, the firewall or the DC which holds the certificate. I have run a new certreq from the DC and then re-keyed the public SSL certificate and re-installed 3 times but the error does not go away and AD Sync with the vendor
    fails. When I run LDP.exe the connection on port 636 fails with "cannot open connection" and the system event log throws the S Channel event 36869 "The SSL server credential's certificate does
    not have a private key information property attached to it"  There is no software firewall set on the DC. When I run Certutil -VerifyStore MY  it shows the current certificates as well as the revoked and expired certificates
    correctly. Certificate 0 is the public cert and is listed with Server and Client authentication, the FQDN of the server is correct and "Certificate is Valid" is listed. The private cert is Certificate 1 and has server and client authentication, the
    FQDN is correct, Private key is not exportable and it ends with Certificate is Valid. I do not see a point in re-keying the cert again until I figure out what the root of the problem is. I have read in some forums that the private cert should not be set to
    expire after the public cert but that does not make a lot of sense when in a situation like this the private cert is of course newer than the public. In fact it is too early to renew the public cert. I have been troubleshooting this for a few days and at this
    point I would have to drop my AD sync with the vendor to LDAP in order to add new users. I do not want to do that for obvious reasons and I do not want to have our spam filtering and email archive service running without Directory sync. Any help would be greatly
    appreciated.

    Hi,
    Have you tried this?
    How to assign a private key to a new certificate after you use the Certificates snap-in to delete the original certificate in Internet Information Services
    http://support.microsoft.com/kb/889651
    Best Regards,
    Amy

  • Intermittent proxy error "There is a problem with the proxy server's security certificate. Outlook is unable to connect to the proxy server "

    Hi all,
    From time to time (at least once a day), the following message pops up on the user's screen:
    "There is a problem with the proxy server's security certificate. Outlook is unable to connect to the proxy server . Error Code 80000000)."
    If we click "OK" it goes away and everything continues to work although sometimes Outlook disconnects. It is quite annoying...
    Any ideas?
    Thank you in advance

    Hi,
    For the security alert issue, I'd like to recommend you check the name in the alert windows, and confirm if the name is in your certificate.
    Additionally, to narrow down the cause, when the Outlook client cannot connect again, I recommand you firstly check the connectivity by using Test E-mail AutoConfiguration. For more information, you can refe to the following article:
    http://social.technet.microsoft.com/Forums/en-US/54bc6b17-9b60-46a4-9dad-584836d15a02/troubleshooting-and-introduction-for-exchange-20072010-autodiscover-details-about-test-email?forum=exchangesvrgeneral
    Thanks,
    Angela Shi
    TechNet Community Support

  • An error occurred searching the certificates for the server. ...

    Hi,
    I am using DSEE 6.2 in Fedora 7
    Each time I access the "Security" tab of my server in DSCC. I get the following error:
    "*An error occurred searching the certificates for the server. An authentication error occurred connecting to xxxxx. Check that the User ID and password are correct*"
    I need to click the "Click here to update authentication" link in the same tab and enter the User ID and password for the user that create the server. The error will gone for this session but reappear as I start a new session in DSCC

    This looks like a known bug. Please log a support case so this can be investigated further
    http://sunsolve.sun.com/search/document.do?assetkey=1-1-6537622-1

  • Sharepoint FBA web application error: Server Error in '/' Application. when login to the web application

    Hello Team,
    I have configured FBA in SharePoint 2010. After the FBA i can get the SQL users using people picker and added users as a site collection admin.
    When i tried to access the site, it shows login page and i have given user name and password then pressed signin button, it's try to redirect the another page and showing below error,
    Server Error in '/' Application.
    Runtime Error 
    Description: An application error occurred on the server. The current custom error settings for this application prevent the details of the application error from being viewed. 
    Details: To enable the details of this specific error message to be viewable on the local server machine, please create a <customErrors> tag within a "web.config" configuration file located in the root directory of the current web application.
    This <customErrors> tag should then have its "mode" attribute set to "RemoteOnly". To enable the details to be viewable on remote machines, please set "mode" to "Off".
    <!-- Web.Config Configuration File -->
    <configuration>
        <system.web>
            <customErrors mode="RemoteOnly"/>
        </system.web>
    </configuration>
    Notes: The current error page you are seeing can be replaced by a custom error page by modifying the "defaultRedirect" attribute of the application's <customErrors> configuration tag to point to a custom error page URL.
    <!-- Web.Config Configuration File -->
    <configuration>
        <system.web>
            <customErrors mode="On" defaultRedirect="mycustompage.htm"/>
        </system.web>
    </configuration>
    "An exception occurred when trying to issue security token: The content type text/html; charset=utf-8 of the response message does not match the content type of the binding (application/soap+msbin1). If using a custom encoder, be sure that the IsContentTypeSupported
    method is implemented properly. The first 1024 bytes of the response were: '<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> 
    <html xmlns="http://www.w3.org/1999/xhtml"> 
    <head> 
    <title>IIS 7.5 Detailed Error - 500.19 - Internal Server Error</title> 
    <style type="text/css"> 
    <!-- 
    body{margin:0;font-size:.7em;font-family:Verdana,Arial,Helvetica,sans-serif;background:#CBE1EF;} 
    code{margin:0;color:#006600;font-size:1.1em;font-weight:bold;} 
    .config_source code{font-size:.8em;color:#000000;} 
    pre{margin:0;font-size:1.4em;word-wrap:break-word;} 
    ul,ol{margin:10px 0 10px 40px;} 
    ul.first,ol.first{margin-top:5px;} 
    fieldset{padding:0 15px 10px 15px;} 
    .summary-container fieldset{padding-bottom:5px;margin-top:4px;} 
    legend.no-expand-all{padding:2px 15px 4px 10px;margin:0 0 0 -12px;} 
    legend{color:#333333;padding:4px 15px 4px 10px;margin:4px 0 8px -12px;_margin-top:0px; 
     border-top:1px solid #EDEDED;border-left:1px solid #EDEDED;border-right:1px solid #969696; 
     border-bottom:1px solid #969696;background:#E7ECF0;font-weight:bold;'..
    I checked sharepoint logs and didn't see any log. but i can see below error logged in  Event viewer application logs,
    I tried changing all customErrors mode and still same error.
    Kindly help me on this, how to resolve the issue.
    Thanks in advance.
    JP

    Hi,
    According to your description, my understanding is that the error occurred when you accessed SharePoint site through form based authentication.
    How did you configure the form based authentication?
    Here is a link about the steps required to configure FBA in SharePoint 2010 for your reference, and check the steps to see if there anything wrong in your configuration:
    http://www.codeproject.com/Articles/352841/How-to-Configure-Form-Based-Authentication-FBA-in
    Through the common error message, we cannot find what exactly caused the error.
    Here is a similar thread for you to take a look:
    http://social.msdn.microsoft.com/Forums/sharepoint/en-US/120ab535-63d2-4205-a51f-1987e9c0cf79/sharepoint-fba-the-content-type-texthtml-charsetutf8-of-the-response-message-does-not-match-the?forum=sharepointgeneralprevious
    Best regards.
    Thanks
    Victoria Xia
    TechNet Community Support

  • Msg 8631 Internal error: Server stack limit has been reached on SQL Server 2012 from T-SQL script that runs on SQL Server 2008 R2

    I have an Script mostly that is generated by SSMS which works with-out issue on SQL Server 2008, but when I attempt to run it on a new fresh install of SQL Server 2012 I get an Msg 8631. Internal error: Server stack limit has been reached. Please look for
    potentially deep nesting in your query, and try to simplify it.
    The script itself doesn't seem to be all that deep or nested.  The script is large 2600 lines and when I remove the bulk of the 2600 lines, it does run on SQL Server 2012.  I'm just really baffled why something that SQL Server generated with very
    few additions/changes AND that WORKS without issue in SQL Server 2008 R2 would suddenly be invalid in SQL Server 2012
    I need to know why my script which is working great on our current SQL Server 2008 R2 servers suddenly fails and won't run on an new SQL Server 2012 server.  This script is used to create 'bulk' Replications on a large number of DBs saving a tremendous
    amount of our time doing it the manual way.
    Below is an 'condensed' version of the script which fails.  I have removed around 2550 lines of specific sp_addarticle statements which are mostly just copy and pasted from what SQL Management Studio 'scripted' for me went I when through the Replication
    Wizard and told it to save to script.
    declare @dbname varchar(MAX), @SQL nvarchar(MAX)
    declare c_dblist cursor for
    select name from sys.databases WHERE name like 'dbone[_]%' order by name;
    open c_dblist
    fetch next from c_dblist into @dbname
    while @@fetch_status = 0
    begin
    print @dbname
    SET @SQL = 'DECLARE @dbname NVARCHAR(MAX); SET @dbname = ''' + @dbname + ''';
    use ['+@dbname+']
    exec sp_replicationdboption @dbname = N'''+@dbname+''', @optname = N''publish'', @value = N''true''
    use ['+@dbname+']
    exec ['+@dbname+'].sys.sp_addlogreader_agent @job_login = N''DOMAIN\DBServiceAccount'', @job_password = N''secret'', @publisher_security_mode = 1, @job_name = null
    -- Adding the transactional publication
    use ['+@dbname+']
    exec sp_addpublication @publication = N'''+@dbname+' Replication'', @description = N''Transactional publication of database
    '''''+@dbname+''''' from Publisher ''''MSSQLSRV\INSTANCE''''.'', @sync_method = N''concurrent'', @retention = 0, @allow_push = N''true'', @allow_pull = N''true'', @allow_anonymous = N''false'', @enabled_for_internet
    = N''false'', @snapshot_in_defaultfolder = N''true'', @compress_snapshot = N''false'', @ftp_port = 21, @allow_subscription_copy = N''false'', @add_to_active_directory = N''false'', @repl_freq = N''continuous'', @status = N''active'', @independent_agent = N''true'',
    @immediate_sync = N''true'', @allow_sync_tran = N''false'', @allow_queued_tran = N''false'', @allow_dts = N''false'', @replicate_ddl = 1, @allow_initialize_from_backup = N''true'', @enabled_for_p2p = N''false'', @enabled_for_het_sub = N''false''
    exec sp_addpublication_snapshot @publication = N'''+@dbname+' Replication'', @frequency_type = 1, @frequency_interval = 1, @frequency_relative_interval = 1, @frequency_recurrence_factor = 0, @frequency_subday = 8,
    @frequency_subday_interval = 1, @active_start_time_of_day = 0, @active_end_time_of_day = 235959, @active_start_date = 0, @active_end_date = 0, @job_login = N''DOMAIN\DBServiceAccount'', @job_password = N''secret'', @publisher_security_mode = 1
    -- There are around 2400 lines roughly the same as this only difference is the tablename repeated below this one
    use ['+@dbname+']
    exec sp_addarticle @publication = N'''+@dbname+' Replication'', @article = N''TABLE_ONE'', @source_owner = N''dbo'', @source_object = N''TABLE_ONE'', @type = N''logbased'', @description = null, @creation_script =
    null, @pre_creation_cmd = N''drop'', @schema_option = 0x000000000803509F, @identityrangemanagementoption = N''manual'', @destination_table = N''TABLE_ONE'', @destination_owner = N''dbo'', @vertical_partition = N''false'', @ins_cmd = N''CALL sp_MSins_dboTABLE_ONE'',
    @del_cmd = N''CALL sp_MSdel_dboTABLE_ONE'', @upd_cmd = N''SCALL sp_MSupd_dboTABLE_ONE''
    EXEC sp_executesql @SQL
    SET @dbname = REPLACE(@dbname, 'dbone_', 'dbtwo_');
    print @dbname
    SET @SQL = 'DECLARE @dbname NVARCHAR(MAX); SET @dbname = ''' + @dbname + ''';
    use ['+@dbname+']
    exec sp_replicationdboption @dbname = N'''+@dbname+''', @optname = N''publish'', @value = N''true''
    use ['+@dbname+']
    exec ['+@dbname+'].sys.sp_addlogreader_agent @job_login = N''DOMAIN\DBServiceAccount'', @job_password = N''secret'', @publisher_security_mode = 1, @job_name = null
    -- Adding the transactional publication
    use ['+@dbname+']
    exec sp_addpublication @publication = N'''+@dbname+' Replication'', @description = N''Transactional publication of database
    '''''+@dbname+''''' from Publisher ''''MSSQLSRV\INSTANCE''''.'', @sync_method = N''concurrent'', @retention = 0, @allow_push = N''true'', @allow_pull = N''true'', @allow_anonymous = N''false'', @enabled_for_internet
    = N''false'', @snapshot_in_defaultfolder = N''true'', @compress_snapshot = N''false'', @ftp_port = 21, @allow_subscription_copy = N''false'', @add_to_active_directory = N''false'', @repl_freq = N''continuous'', @status = N''active'', @independent_agent = N''true'',
    @immediate_sync = N''true'', @allow_sync_tran = N''false'', @allow_queued_tran = N''false'', @allow_dts = N''false'', @replicate_ddl = 1, @allow_initialize_from_backup = N''true'', @enabled_for_p2p = N''false'', @enabled_for_het_sub = N''false''
    exec sp_addpublication_snapshot @publication = N'''+@dbname+' Replication'', @frequency_type = 1, @frequency_interval = 1, @frequency_relative_interval = 1, @frequency_recurrence_factor = 0, @frequency_subday = 8,
    @frequency_subday_interval = 1, @active_start_time_of_day = 0, @active_end_time_of_day = 235959, @active_start_date = 0, @active_end_date = 0, @job_login = N''DOMAIN\DBServiceAccount'', @job_password = N''secret'', @publisher_security_mode = 1
    -- There are around 140 lines roughly the same as this only difference is the tablename repeated below this one
    use ['+@dbname+']
    exec sp_addarticle @publication = N'''+@dbname+' Replication'', @article = N''DB_TWO_TABLE_ONE'', @source_owner = N''dbo'', @source_object = N''DB_TWO_TABLE_ONE'', @type = N''logbased'', @description = null, @creation_script
    = null, @pre_creation_cmd = N''drop'', @schema_option = 0x000000000803509D, @identityrangemanagementoption = N''manual'', @destination_table = N''DB_TWO_TABLE_ONE'', @destination_owner = N''dbo'', @vertical_partition = N''false''
    EXEC sp_executesql @SQL
    fetch next from c_dblist into @dbname
    end
    close c_dblist
    deallocate c_dblist
    George P Botuwell, Programmer

    Hi George,
    Thank you for your question. 
    I am trying to involve someone more familiar with this topic for a further look at this issue. Sometime delay might be expected from the job transferring. Your patience is greatly appreciated. 
    Thank you for your understanding and support.
    If you have any feedback on our support, please click
    here.
    Allen Li
    TechNet Community Support

  • There is a problem with the proxy server's security certificate. The name on the security certificate is invalid or does not match the name of the target site "Mailserver"

    Good day Guys
    First of all I am not an Exchange Expert, and I might be asking a very stupid question, but please bare with me. :) 
    While I was on leave our Mail server fell over and The company got a Specialist to help out for the time being.
    We where\are on Microsoft Exchange 2007 , which Fell over, and the specialist was able to recover as much data as he could.
    They then installed Exchange 2013 and tried to migrate everything from 2007 to 2013 and not everything migrated over.
    But the problem is, Outlook Anywhere was enable on 2007 and worked a 100% (before the disaster)
    With Exchange 2013 I get the following error message when trying to connect With Outlook 2013, using an external connection:
    "There is a problem with the proxy server's security certificate. The name on the security certificate is invalid or does not match the name of the target site "Mailserver"
    Outlook is unable to connect to the Proxy server. (Error Code 0)"
    Has anyone had the Similar when migrating over from 2007 to 2013 or is this an Issue on IIS and nothing to do with Exchange migration?
    Your assistance will be greatly appreciated.

    Hi,
    Firstly, I would suggest we use Exchange 2013 FE as the Outlook Anywhere proxy server.
    For the certificate issue, it mostly occurs because the host name that Outlook are trying to access does not match the certificate SAN. Please check with this point. If they do not match, you
    can change the host name by referring to the following article:
    https://support.microsoft.com/kb/940726/en-us?wa=wsignin1.0
    Thanks,
    Simon Wu
    TechNet Community Support

  • Project server and exhcnage certificate or EWS url problem

    We are having trouble enabling synchronization between our Project 2010 Server and our Exchange 2010 CAS server. 
    When we initially saw this error below,
    “The root of the certificate chain is not a trusted root authority.”, we then downloaded the GoDaddy intermediates certificate that goes with the “mail.sfbcic.com” cert and    imported it as a trusted root authority
    on the project server.  However, we are still getting the error you see below. 
    You can see that we have two certificates that are valid. 
    Our CAS server has 2 certificates: (Both are valid certificates)
                    1 – Self-Signed      HOSEXCHCAS4
                    2 – Third-party (GoDaddy) certificate      mail.sfbcic.com
    Our Questions:
    1. In PWA, do the computer names of the cas servers need to match the third party certificate (is that what's causing the error)?  Currently, we have the CAS server names listed (cas2, cas3, cas 4).  The Go Daddy certificate
    is for mail.ourdomain.com
    2 If the answer is no, do you have any idea what we are missing?
    3. Do we need to get a new third party certificate and not use the self-signed certificate?
    4.  Would one of the CAS servers not being active right now cause this issue?
    -------  Event logs ---------------------
    Log Name:      Application
    Source:        Microsoft-SharePoint Products-SharePoint Foundation
    Date:          4/18/2012 4:11:08 PM
    Event ID:      8311
    Task Category: Topology
    Level:         Error
    Keywords:     
    User:          DOMAIN1\svc_spfarm
    Computer:      HOPROJECTSVR.sfbcic.com
    Description:
    An operation failed because the following certificate has validation errors:\n\nSubject Name: CN=mail.sfbcic.com, OU=Information Technology, O=Southern Farm Bureau Casualty Insurance Company, L=Ridgeland, S=MS, C=US\nIssuer Name:
    SERIALNUMBER=xxxxxx, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US\nThumbprint:
    xxxxxxxxxxxxxxxxxxxxxxxxxxxx\n\nErrors:\n\n The root of the certificate chain is not a trusted root authority..
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-SharePoint Products-SharePoint Foundation" Guid="{6FB7E0CD-52E7-47DD-997A-241563931FC2}" />
        <EventID>8311</EventID>
        <Version>14</Version>
        <Level>2</Level>
        <Task>13</Task>
        <Opcode>0</Opcode>
        <Keywords>0x4000000000000000</Keywords>
        <TimeCreated SystemTime="2012-04-18T21:11:08.362997800Z" />
        <EventRecordID>12044</EventRecordID>
        <Correlation ActivityID="{09F06ACB-9929-4F57-A7E8-9786C165ECAE}" />
        <Execution ProcessID="5424" ThreadID="1200" />
        <Channel>Application</Channel>
        <Computer>HOPROJECTSVR.sfbcic.com</Computer>
        <Security UserID="xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" />
      </System>
      <EventData>
        <Data Name="string0">CN=mail.sfbcic.com, OU=Information Technology, O=Southern Farm Bureau Casualty Insurance Company, L=Ridgeland, S=MS, C=US</Data>
        <Data Name="string1">SERIALNUMBER=xxxxxxxxx, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository,
    O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US</Data>
        <Data Name="string2">xxxxxxxxxxxxxxxxxxxxxxxxxxx</Data>
        <Data Name="string3">The root of the certificate chain is not a trusted root authority.</Data>
      </EventData>
    </Event>
    Exchange queue errors…..
    ExchangeSync() failed to retrieve specified user_s      (c3d0c753-21b3-4ff1-8312-61fba2defe8e) Exchange Server url. No exception     
    was thrown, but EWS url came back empty.:
    ExchangeSyncEWSUrlFailed (40509). Details: id='40509'      
    name='ExchangeSyncEWSUrlFailed' uid='42585c0c-d4b2-4dfc-9303-af128e5e3a00'       teamMemberUid='c3d0c753-21b3-4ff1-8312-61fba2defe8e'.
    ExchangeSyncEWSUrlFailed (40509). Details: id='40509'      
    name='ExchangeSyncEWSUrlFailed'       uid='5a607457-2eb4-4d53-a80e-13e538fb46ff'       teamMemberUid='c3d0c753-21b3-4ff1-8312-61fba2defe8e'.
    ExchangeSyncEWSUrlFailed (40509). Details: id='40509'      
    name='ExchangeSyncEWSUrlFailed'       uid='490d7241-a2b9-42f5-b81b-a4f3ee67c2a6'       teamMemberUid='c3d0c753-21b3-4ff1-8312-61fba2defe8e'.
    ExchangeSyncEWSUrlFailed (40509). Details: id='40509'      
    name='ExchangeSyncEWSUrlFailed'       uid='eefd753b-a3da-4a17-a278-bf12fc68e58c'       teamMemberUid='c3d0c753-21b3-4ff1-8312-61fba2defe8e'.
    ExchangeSyncEWSUrlFailed (40509). Details: id='40509'      
    name='ExchangeSyncEWSUrlFailed' uid='f525cd5e-2a57-414b-a20d-1dc2528733e9'       teamMemberUid='c3d0c753-21b3-4ff1-8312-61fba2defe8e'.
    ExchangeSyncEWSUrlFailed (40509). Details: id='40509'      
    name='ExchangeSyncEWSUrlFailed'       uid='34f74c12-a812-4a80-85a3-0ece1e426f33'       teamMemberUid='c3d0c753-21b3-4ff1-8312-61fba2defe8e'.
    ExchangeSync() handle ExchangeSyncStatusingMessage for      user c3d0c753-21b3-4ff1-8312-61fba2defe8e queue message caused an     
    exception.:
    ExchangeSyncGeneralProcessingFailure (40512). Details: id='40512'      
    name='ExchangeSyncGeneralProcessingFailure' uid='7b7ab045-ba46-47cd-8504-23272e09dbcc'       teamMemberUid='c3d0c753-21b3-4ff1-8312-61fba2defe8e'       exception='Microsoft.Office.Project.Server.BusinessLayer.Queue.ExchangeSyncEmailAddressInvalidException:
          Could not find Exchange server for resource       c3d0c753-21b3-4ff1-8312-61fba2defe8e at       Microsoft.Office.Project.Server.BusinessLayer.Queue.ProcessExchangeSyncMessage.ExecuteSync(ExchangeSyncTasks
          exchangeSyncTasks) at       Microsoft.Office.Project.Server.BusinessLayer.Queue.ProcessExchangeSyncMessage.HandleMessage(Message       msg, Group messageGroup, JobTicket jobTicket,
    MessageContext mContext)'.
    ExchangeSyncGeneralProcessingFailure (40512). Details: id='40512'      
    name='ExchangeSyncGeneralProcessingFailure'       uid='a3783e9a-2b39-4878-8099-20681a4715d3'       teamMemberUid='c3d0c753-21b3-4ff1-8312-61fba2defe8e'       exception='Microsoft.Office.Project.Server.BusinessLayer.Queue.ExchangeSyncEmailAddressInvalidException:
          Could not find Exchange server for resource       c3d0c753-21b3-4ff1-8312-61fba2defe8e at       Microsoft.Office.Project.Server.BusinessLayer.Queue.ProcessExchangeSyncMessage.ExecuteSync(ExchangeSyncTasks
          exchangeSyncTasks) at       Microsoft.Office.Project.Server.BusinessLayer.Queue.ProcessExchangeSyncMessage.HandleMessage(Message       msg, Group messageGroup, JobTicket jobTicket,
    MessageContext mContext)'.
    ExchangeSyncGeneralProcessingFailure (40512). Details: id='40512'      
    name='ExchangeSyncGeneralProcessingFailure'       uid='71656d71-38d4-4acf-a26d-9f0d6f84da0b'       teamMemberUid='c3d0c753-21b3-4ff1-8312-61fba2defe8e'       exception='Microsoft.Office.Project.Server.BusinessLayer.Queue.ExchangeSyncEmailAddressInvalidException:
          Could not find Exchange server for resource       c3d0c753-21b3-4ff1-8312-61fba2defe8e at       Microsoft.Office.Project.Server.BusinessLayer.Queue.ProcessExchangeSyncMessage.ExecuteSync(ExchangeSyncTasks
          exchangeSyncTasks) at       Microsoft.Office.Project.Server.BusinessLayer.Queue.ProcessExchangeSyncMessage.HandleMessage(Message       msg, Group messageGroup, JobTicket jobTicket,
    MessageContext mContext)'.
    ExchangeSyncGeneralProcessingFailure (40512). Details: id='40512' name='ExchangeSyncGeneralProcessingFailure'
          uid='2454abb1-6a2b-4716-bd45-03a7edf80347'       teamMemberUid='c3d0c753-21b3-4ff1-8312-61fba2defe8e'       exception='Microsoft.Office.Project.Server.BusinessLayer.Queue.ExchangeSyncEmailAddressInvalidException:
          Could not find Exchange server for resource       c3d0c753-21b3-4ff1-8312-61fba2defe8e at       Microsoft.Office.Project.Server.BusinessLayer.Queue.ProcessExchangeSyncMessage.ExecuteSync(ExchangeSyncTasks
          exchangeSyncTasks) at       Microsoft.Office.Project.Server.BusinessLayer.Queue.ProcessExchangeSyncMessage.HandleMessage(Message       msg, Group messageGroup, JobTicket jobTicket,
    MessageContext mContext)'.
    ExchangeSyncGeneralProcessingFailure (40512). Details: id='40512'      
    name='ExchangeSyncGeneralProcessingFailure'       uid='3dbd4f65-f478-47e7-aeb3-d05575be69fe'       teamMemberUid='c3d0c753-21b3-4ff1-8312-61fba2defe8e'       exception='Microsoft.Office.Project.Server.BusinessLayer.Queue.ExchangeSyncEmailAddressInvalidException:
          Could not find Exchange server for resource       c3d0c753-21b3-4ff1-8312-61fba2defe8e at Microsoft.Office.Project.Server.BusinessLayer.Queue.ProcessExchangeSyncMessage.ExecuteSync(ExchangeSyncTasks      
    exchangeSyncTasks) at       Microsoft.Office.Project.Server.BusinessLayer.Queue.ProcessExchangeSyncMessage.HandleMessage(Message       msg, Group messageGroup, JobTicket jobTicket, MessageContext mContext)'.
    ExchangeSyncGeneralProcessingFailure (40512). Details: id='40512'      
    name='ExchangeSyncGeneralProcessingFailure'       uid='17a05fda-8702-4e20-93d1-068bf9182cf1'       teamMemberUid='c3d0c753-21b3-4ff1-8312-61fba2defe8e' exception='Microsoft.Office.Project.Server.BusinessLayer.Queue.ExchangeSyncEmailAddressInvalidException:
          Could not find Exchange server for resource       c3d0c753-21b3-4ff1-8312-61fba2defe8e at       Microsoft.Office.Project.Server.BusinessLayer.Queue.ProcessExchangeSyncMessage.ExecuteSync(ExchangeSyncTasks
          exchangeSyncTasks) at       Microsoft.Office.Project.Server.BusinessLayer.Queue.ProcessExchangeSyncMessage.HandleMessage(Message       msg, Group messageGroup, JobTicket jobTicket,
    MessageContext mContext)'.
    Queue:     
    GeneralQueueJobFailed (26000) -
    ExchangeSyncTasks.ExchangeSyncTasks. Details: id='26000' name='GeneralQueueJobFailed' uid='cfd94c57-78c0-4c1a-b343-22e36d940276' JobUID='11ff22eb-364b-4ff6-a05f-10e29407e04a' ComputerName='HOPROJECTSVR' GroupType='ExchangeSyncTasks' MessageType='ExchangeSyncTasks'
    MessageId='1' Stage=''. For more details, check the ULS logs on machine
    HOPROJECTSVR for entries with JobUID 11ff22eb-364b-4ff6-a05f-10e29407e04a.
    Cletus51

    We found the problem. 
    We downloaded the "Go Daddy Class 2 Certification Authority Root Certificate".  Via Sharepoint 2010 Central Administration, we created a new trust relationship using the certificate we downloaded. 
    Cletus51

  • Sharepoint 2013 runtime error: Server Error in '/' Application.

    Morning Ladies and Gentlemen,
    I am an Intern in a mining company that decided to use sharepoint as their intranet system. Everything was going fine upto yesterday. I don't know if this might be the source of the problem, but after my boss asked for the IP Address for PING. After that,
    I first got an error 404. Then a decision was made to restart the Server (Server is on Amazon, and we access it remotely).
    I'm getting the following error:
    Server Error in '/' Application.
    Runtime Error
    Description: An application error occurred on the server. The current custom error settings for this application prevent the details of the application error from being viewed remotely (for security reasons). It could, however,
    be viewed by browsers running on the local server machine.           
    Details: To enable the details of this specific error message to be viewable on remote machines, please create a <customErrors> tag within a "web.config" configuration file located in the root directory of the current web application.
    This <customErrors> tag should then have its "mode" attribute set to "Off".
    <!-- Web.Config Configuration File -->
    <configuration>
    <system.web>
    <customErrors mode="Off"/>
    </system.web>
    </configuration>
    Notes: The current error page you are seeing can be replaced by a custom error page by modifying the "defaultRedirect" attribute of the application's <customErrors> configuration tag to point to a custom error page URL.
    <!-- Web.Config Configuration File -->
    <configuration>
    <system.web>
    <customErrors mode="RemoteOnly" defaultRedirect="mycustompage.htm"/>
    </system.web>
    </configuration>

    Hi Avinash
    Thanks for your quick reply.
    I have tried the steps you described and now I'm getting an Error 500.
    But I cannot see anywhere into the web.config filr the tag "trace".
    My project manager told me that the problem wasn't into the web.config file but the problem has to do with the server being out of the domain. Now the server is back into the domain and I can't really connect my Sharepoint to the FARM.
    I'm so confused but I'm still convinced the problem is in the web.config. Is there any onther technic I can use to fix this problem?
    Thanks again for your help

  • Uwc-common-error-server-misconfig

    Hello
    some user from a domain are experiencing this problem. when loggin to uwc
    An error occurred during this operation
    uwc-common-error-server-misconfig
    the version of the messaging server is :
    Sun Java(tm) System Messaging Server 6.2-8.04 (built Feb 28 2007)
    libimta.so 6.2-8.04 (built 19:28:07, Feb 28 2007)
    SunOS jesmail 5.9 Generic_118558-21 sun4u sparc SUNW,Sun-Fire-V440
    and uwc:
    showrev -p | grep uwc
    Patch: 118540-21 Obsoletes: 117287-99, 117819-13, 119156-07 Requires: Incompatibles: Packages: SUNWuwc
    Patch: 118540-42 Obsoletes: 117287-99, 117819-13, 119156-07 Requires: Incompatibles: Packages: SUNWuwc
    after the page is reloaded the problem is gone. I checked the error log in the ldap and found the following error:
    [28/Jul/2008:15:18:25 +0200] - ERROR<5895> - Schema - conn=150153 op=56 msgId=14565 - User error: Entry "uid=g1580060, ou=People, o=linter.be,o=jes.vera.be", single-valued attribute "sunUCDateFormat" has multiple values
    how can I fix this attribute for this user because not all the user from the domain suffer from it. are there any special procedures to do it.
    thank you .

    mario_garcia wrote:
    [28/Jul/2008:15:18:25 +0200] - ERROR<5895> - Schema - conn=150153 op=56 msgId=14565 - User error: Entry "uid=g1580060, ou=People, o=linter.be,o=jes.vera.be", single-valued attribute "sunUCDateFormat" has multiple values
    how can I fix this attribute for this user because not all the user from the domain suffer from it. are there any special procedures to do it.Do all the users experiencing the problem have multiple sunUCDateFormat: attributes?
    When did the user(s) start experiencing the problem and what did you change around this time e.g. new patch to UWC, upgraded Directory Server..?
    There is a known bug with Directory Server that can result in the exact error you provided -- bug#6294113 - "DS5.2p3- after first empty replace op. on single-valued attribute no futher add possible - rpl. on".
    The fix is to upgrade to DS5.2p6.
    Note however that the directory values that were 'broken' due to the above bug need to be manually fixed post-applying the directory server patch (the patch only stops future occurrences of the problem). Contact Sun Support to get a copy of the scripts to help you identify and repair these entries.
    Regards,
    Shane.

  • Server 2008 R2 Certificate services web enrollment

    Not sure if this is the right place for this, but here goes.
    Upgraded a domain to 2008 R2. Migrated certificate services to 2008 R2 Enterprise root on a member server.
    Autoenrollment works fine
    Requesting cert from the MMC using certificates snapin works fine
    Requesting a cert via the web https://servername/certsrv gets the following error;
    Active Directory Certificate Services denied request 12345 because the request subject name is
    invalid or too long 0x80094001 (-2146877439)
    Error constructing or publiching certificate.
    I created a new cert template and did NOT check use Active Directory for subject name as templates with this checked
    do not show up in the web enrollment interface.
    I have enabled this template for enrollment and gave users rights to enroll.
    They are clicking advanced in the web interface as they want a computer cert.
    For the subject name, they enter computername.domain.local
    Based on searches I've done on the InterWeb, permissions APPEAR to be correct.
    Again, Autoenroll and MMC work just fine. Appears to be confined to only web.

    They are clicking advanced in the web interface as they want a computer cert.
    For the subject name, they enter computername.domain.local
    Be aware that the web enrollment pages does not support computer certificates and you need to issue the certificate to the user and import it to the computer store
    /Hasain

  • Error "server with secure communication unavailable" when adding iCloud account to iCal

    I have set up iCloud and activated the Calendars option, but can see iCloud in iCal. Whenever I try to manually add an iCloud account from the iCal preferences I get an error "Server with secure communication unavailable" and it won't add the iCloud account.
    Does anybody have a soluton for this issue?

    Hi I think I have tried this correctly but it just doesn't work for me I am replacing with:
    https://www.google.com/calendar/dav/[email protected]/user//www.google.com/calendar/dav/[email protected]/user
    my company email address and I have tried with /user at the end and without and am not using gmail but still no go, I have just upgraded to Air and its driving me crackers that this no longer works.
    Any other suggestions welcome :/

  • Mail cannot verify my mail server's root certificate

    When I try to send an email, I get a warning message saying that mail cannot verify my mail servers root certificate. I have tested the certificate and it had a blue boarder not a gold one, I can't remember what this means but I think its not recognised. This has only just started happening.
    Apparently the root server is VeriSign Class 3 Extended Validation
    Mail was unable to verify the identity of this server, which has a certificate issued to "smtp.mac.com". The error was:
    The root certificate for this server could not be verified.
    You might be connecting to a computer that is pretending to be "smtp.mac.com", and putting your confidential information at risk. Would you like to continue anyway?

    This is the OS X Server forum.... You probably want to post in:
    http://discussions.apple.com/forum.jspa?forumID=1223
    Jeff

  • Sending an Email via ColdFusion as a Service leads to ActionScript-Error "Server is undefined to setup the connection"

    Hi,
    Ben Forta shows in his video "ColdFusion9 exposed as Flex Services" how to send an Email using ColdFusion as a Service.
    I tried out this example with Flashbuilder4 Beta2 but I got the following ActionSript-Error:
    Error: Server is undefined to setup the connection
        at coldfusion.service::BasicService/initializeConnection()[D:\p4\depot\ColdFusion\cf_main\to ols\AIRIntegration\Services\src\coldfusion\service\BasicService.as:278]
        at coldfusion.service::BasicService/call()[D:\p4\depot\ColdFusion\cf_main\tools\AIRIntegrati on\Services\src\coldfusion\service\BasicService.as:226]
        at coldfusion.service.mxml::Mail/execute()[D:\p4\depot\ColdFusion\cf_main\tools\AIRIntegrati on\Services\src\coldfusion\service\mxml\Mail.as:370]
        at CFaaS/button1_clickHandler()[C:\Dokumente und Einstellungen\walter\Adobe Flash Builder Beta 2\CFaaS\src\CFaaS.mxml:18]
        at CFaaS/___CFaaS_Button1_click()[C:\Dokumente und Einstellungen\walter\Adobe Flash Builder Beta 2\CFaaS\src\CFaaS.mxml:93]
    Who has an idea what to do?
    Thanks in advance,
    Walter

    Hi,
    We tried this out and it works like a charm
    Actually even we hit the issue you have mentioned but on further investigation we could get things working.
    Please follow these settings, we are not sure if you have done all of these:
    a) In CF9 administrator, under Mail section please type your server name, username and password. Check the ' Verify mail server connection'
    checkbox and click 'Submit Changes'. Make sure you get the message 'Connection Verification Successful'.
    b) Under Security-> 'User Manager' section in CF9 administration,  add an user using 'Add User' with the following info:
    username, password, confirm password , check both RDS and administrative access and add 'Exposed Services' by selecting the required services.
    eg: Mail Service and click 'Add User'.
    c) Go to 'Security->Allow IP Address in CF9 administrator and enter your IP address and say 'Add'.
    d) After add the following tag in addition to CF:Mail,
    <cf:Config  cfServer="" cfPort="8501" servicePassword="" serviceUserName="" />(the values entered here should be same as the ones configured under 'Add User' and 'Allow IP address' section).
    Please find attached the mxml file (TestCF.mxml) which has the Flex code.
    Also, add the 'CFService.swc' into your project. Go to  Project->Flex Build Path->Add SWC and point to D:\ColdFusionCentaur\wwwroot\CFIDE\scripts\air (subject to CF9 installed location).
    Please try the workflow by following these steps and let us know if things work fine
    Thanks,
    Balaji
    http://balajisridhar.wordpress.com

  • There is a problem with the server's security certificate. The security certificate is not from a trusted certifying authority. SAP Business One is unable to connect to the server

    Hello,
    I have an issue with connecting client SB1H on Windows, the scenario is as follows:
    1.- Server:
         Suse Linux Enterprise Server 11.3 kernel version: 3.0.76-0.11 IBM
         NDB and Server are review 69 SP06
    2.- Client:
         Windows 8 Pro Virtual Machine on Microsoft Hyper-V
         SB1H PL 11 version 32bits    
         SAP HANA Studio version 1.0.60
    When I run SB1H the following message appears:
    There is a problem with the server's security certificate. The security certificate is not from a trusted certifying authority. SAP Business One is unable to connect to the server.
    Any idea what could be the solution?

    Hi,
    Please check SAP notes:
       1993392 - Server components setup wizard: New default values for certificates and single sign-on option
    1929288 - Do not configure SSL for XApp during installation or upgrade if XApp is installed on a different machine than the SAP HANA server
    Thanks & Regards,
    Nagarajan

Maybe you are looking for

  • Insert with Nested Table

    Hi, I have a table called time_slots CREATE OR REPLACE TYPE type_timeslots AS TABLE OF DATE; CREATE TABLE time_slots time_code VARCHAR2(50), TIME_SLOT TYPE_TIMESLOTS NESTED TABLE TIME_SLOT STORE AS NESTED_TIME_SLOTS I have a SQL which returns multipl

  • ORA-01435--urgent please help me

    Hi friend.. I installed oracle 11g Release1 downloaded from oracle corporation website and trying to configure oracle APEX as embed pl/sql getway, got an error while.. @apxconfig.. SQL> @e:\Softwares\oracle_APEX\apex_3.2\apex\apxconf.sql PORT 8080 En

  • How to drawing on image.

    Hi, I am developing one paint program. I am drawing over an image but the image is wash out when i am dragging mouse on canvas. But when i am clicking first on canvas before selecting any button. then selecting button after that it is working fine. P

  • FIM data upload issues

    Hi When i am using FIM 10.0 to upload data from flat file i get an error as follows: Failed to generate ATL file: The job launch for job 'test_FF' failed with error 'The repository bods for the batch job test_FF cannot be found.' Experts please advis

  • How to call single vi in multiple windows

    i have one single graph accessing data through global variable in a file grpah.vi.  Graph runs in a while loop. In my main vi, i have 4 sub panels. pressing respective buttons should display graphs in respective sub panels using graph.vi . I am using