Importing third party certificate
I'm trying to import a third party test SSL certificate (infact I have
tried several including one from thawte, instantSSL) using ConsoleOne
v1.3.6f. I have Certificate server v2.23 build 34 snapin and nici
2.7.0-2. I created the CSR without a problem.
Each time I try to import the certificate, when I click on Finish,
ConsoleOne just shuts down. No error messages. Nothing.
When I restart ConsoleOne, the certificate hasn't been imported.
Have tried ConsoleOne on other workstations with the same result.
Slawrence,
It appears that in the past few days you have not received a response to your
posting. That concerns us, and has triggered this automated reply.
Has your problem been resolved? If not, you might try one of the following options:
- Do a search of our knowledgebase at http://support.novell.com/search/kb_index.jsp
- Check all of the other support tools and options available at
http://support.novell.com.
- You could also try posting your message again. Make sure it is posted in the
correct newsgroup. (http://support.novell.com/forums)
Be sure to read the forum FAQ about what to expect in the way of responses:
http://support.novell.com/forums/faq_general.html
If this is a reply to a duplicate posting, please ignore and accept our apologies
and rest assured we will issue a stern reprimand to our posting bot.
Good luck!
Your Novell Product Support Forums Team
http://support.novell.com/forums/
Similar Messages
-
Error While importing third party certificate
Hi,
In my application I'm using HTTPS for secure connectivity.For that purpose I signed my midlet using a third Party certificate (GoDaddy's Certificate).But when I'm hitiing the url it is not working.
I've done this with generating my own certificate with Tomcat.It is working fine there.I followed the following topic to create Certificate for TomCat
http://143.129.203.3/s/sitter/sl2nap/javaSSLprogr.htm
but when i'm hitiing some live url then it is not working!
Please provide me proper help if possible
Thanx in advanceSlawrence,
It appears that in the past few days you have not received a response to your
posting. That concerns us, and has triggered this automated reply.
Has your problem been resolved? If not, you might try one of the following options:
- Do a search of our knowledgebase at http://support.novell.com/search/kb_index.jsp
- Check all of the other support tools and options available at
http://support.novell.com.
- You could also try posting your message again. Make sure it is posted in the
correct newsgroup. (http://support.novell.com/forums)
Be sure to read the forum FAQ about what to expect in the way of responses:
http://support.novell.com/forums/faq_general.html
If this is a reply to a duplicate posting, please ignore and accept our apologies
and rest assured we will issue a stern reprimand to our posting bot.
Good luck!
Your Novell Product Support Forums Team
http://support.novell.com/forums/ -
How do i use Third Party certificates when setting up Lync 2013
Hi,
I'm currently installing a trial of Lync 2013 for my company and it has got to the stage of adding in certificates. My company have no wish to add in a Certificate Authority unless its vital, they have asked if its possible to use a third party certificate
provider. I have no idea how to go about this and would appreciate any help on where to get a certificates from as well as how to import these into Lync.
Many thanks
JohnYes it is possible. Thankfully Lync makes it very easy. When you deploy Lync one of the steps in the Lync Deployment Tool is to Request and Assign Certificates.
It's a wizard that will create the CSR for you and basically include all the required names.
You will however need UCC certificates for most things (that support multiple Subject Alternate Names) so it may get a little expensive.
The CA you choose is really up to you, but GoDaddy do some pretty reasonably priced UCC certificates. Digicert is also another commonly used CA
If this helped you please click "Vote As Helpful" if it answered your question please click "Mark As Answer" | Blog
www.lynced.com.au | Twitter
@imlynced -
Try to implement SSL for OMS console - Third Party Certificate
Using 10.2.0.5.0 of Grid control. 11.1.0.7.0 DB
Internet Explorer (or any browser)
enter
https://hostname.com:1159/em/
gets
There is a problem with this website's security certificate.
The security certificate presented by this website was not issued by a trusted certificate authority.
Security certificate problems may indicate an attempt to fool you or intercept any data you send to the server.
We recommend that you close this webpage and do not continue to this website.
Click here to close this webpage.
Continue to this website (not recommended).
I have tried to follow instructions in Method 2
http://download.oracle.com/docs/cd/B16240_01/doc/em.102/e10954/security2.htm
emctl secure oms -trust_certs_loc <loc of trusted_certs.txt>
completes without error
I have a third party certificate from GEOTRUST. I have downloaded the Root CA certificate from GEOTRUST and placed them both in a file called trusted_certs.txt
I have also imported both certificates in Oracle Wallet Manager. I can see the details within OWM and they are correct.
I followed instructions in metalink How to provide HTTPS browser access to the Grid Control Console using a third party certificate? [ID 736103.1]
When I view the certificate from IE after 'opmnctl startall', the cert is from grid control not GEOTRUST.
It seems like the 'emctl secure oms ...' overwrites the wallet in $OMS_HOME/sysman/wallets/oms_hostname
SSL is a part of Oracle's Best Practices for Grid Control but has anyone gotten it to work?
Thanks in advance.These Certifications Authorities are supposed to work out of the box:
Class 1 Public Primary Certification Authority by VeriSign, Inc.
■ Class 2 Public Primary Certification Authority by VeriSign, Inc.
■ Class 3 Public Primary Certification Authority by VeriSign, Inc.
■ Secure Server Certification Authority by RSA Data Security, Inc.
■ GTE CyberTrust Root by GTE Corporation
■ GTE CyberTrust Global Root by GTE CyberTrust Solutions, Inc.
■ Entrust.net Secure Server Certification Authority by Entrust.net ((c) 1999
■ Entrust.net Limited, www.entrust.net/CPS incorp. by ref. (limits liab.))
■ Entrust.net Certification Authority (2048) by Entrust.net ((c) 1999
■ Entrust.net Limited, www.entrust.net/CPS_2048 incorp. by ref. (limits liab.))
■ Entrust.net Secure Server Certification Authority by Entrust.net ((c) 2000
■ Entrust.net Limited, www.entrust.net/SSL_CPS incorp. by ref. (limits liab.))
Has anyone used these with OEM?
Verisign is $600 year - ouch
Entrust is $200 -
Third party Certificate not showing up in SQL configuration manager drop down box
Hi,
I have an SQL instance that needs to use a third party SSL certificate for all communications to that SQL instance. I have installed my third party certificate via MMC and it is showing under the Personal Folder.
However, when i go into the SQL configuration manager and right click the instance name > Properties > Certificates, it is not showing in the drop down box.
I am currently using MS SQL Server 2008 R2, which is installed on Windows Server 2012.Hi,
If the certificate cannot be used for SQL Server and hence will not be visible in SQL Configuration manager. Check the validity of the installed certificate. It may not has the correct DNS name.
I suggest you request a new third party certificate from the vendor with the correct DNS name. Install it on SQL Server environment, then you should see certificate form the configuration manager dropdown box.
Thanks.
Tracy Cai
TechNet Community Support -
Generate CSR for Third-Party Certificates
Hi All,
i have an issue when i tried to Generate CSR for Third-Party Certificates,
i follow step by step in the document of cisco until this step:
3.
Now that your CSR is ready, copy and paste the CSR information into any CA enrollment tool.
In order to copy and paste the information into the enrollment form, open the file in a text editor that
does not add extra characters. Cisco recommends that you use Microsoft Notepad or UNIX vi. Refer
to the website of the third−party CA for more information on how to submit the CSR through the
enrollment tool.
After you submit the CSR to the third−party CA, the third−party CA digitally signs the certificate and
sends back the signed certificate via e−mail.
4.
Copy the signed certificate information that you receive back from the CA into a file.
This example names the file CA.pem.
my issue is where i sould copy and paste the CSR information into any CA enrollment tool. i just have done create mykey.pem and myreq.pem in my folder OpenSSL\bin
Please help and Thanks you.
Regards,
Jasayou have to do more steps using openssl.
before you obtain the third−part certificate, you have to copy that on a notepad text, and you have to obtain an intermediate and root certificate from the company that gives you the certificate.
Then you have to copy and paste on a notepad or gedit:
SSL (the certificate that they give you)
Intermediate (the certificate that you obtain from the company that gives you the certificate)
Root (the certificate that you obtain from the company that gives you the certificate)
name the text file like: allcerts.pem
then... you have to run this commands:
C:\OpenSSL\bin>openssl pkcs12 -export -in allcerts.pem -inkey mykey.pem -out All-certs.p12 -clcerts -passin pass:yourpassword -passout pass:yourpassowrd
C:\OpenSSL\bin>openssl pkcs12 -in All-certs.p12 -out finalcert.pem -passin pass:yourpassword -passout pass:yourpassword
Then you are going to have a file named: finalcert.pem, thats the one you have to update to the WLC. please note that on those lines "yourpassword" is the password you use when you create the certificate and its going to be the same that you have to use for upload to WLC.
Note that you have to use openssl version 0.9.8 because its the only version thats WLC support
If you have doubts please contact me.
Have fun! -
How to import Third party application through SAP in ABAP
Hello,
This is regarding importing third party application or non sap application through SAP or through portal...
is there any way to do the same?
actually our organization is having one independent application developed on .NET platform. we need to connect that in mY SAP R/3. so pls suggest me some proper way to achieve this one.
regards,
jigar
[email protected]You can connect to SAP from a .Net application using the .NET connectors. Please find the help below
http://help.sap.com/saphelp_nw2004s/helpdata/en/e9/23c80d66d08c4c8c044a3ea11ca90f/content.htm
http://www.microsoft-sap.com/overview_sap_connector.html
http://www.sapgenie.com/interfaces/netconnector.htm
Regards,
Ravi
Note : Please mark all the helpful answers -
Import third party designs in an Oracle BPM Process
Hi,
Is there currently any capability in the BPM suite to import third party process designs?Thanks,
I was asking more in terms of a general 'import' feature that used to be available earlier (rather than BPA to BPM in particular - which is also probably enabled by XPDL)
see this: http://blogs.oracle.com/ptslad/2008/12/hi_folks_i_would_like.html
PS: ARIS is a product in its own standing and not called Oracle BPA Suite now.
http://www.ids-scheer.com/en/ARIS_ARIS_Platform/3730.html
BPA Suite is 'based on' ARIS (and always has been, AFAIK)
http://www.oracle.com/technologies/soa/bpa-suite.html
Regards,
Jang-Vijay -
Importing third-party java libraries
I have just downloaded jakarta httpclient and am trying to get it to work with a program I am writing. Are there instructions somewhere on importing third-party libraries? I've searched these forums, the tutorials, and even google and haven't found any. Or can someone just tell me how to do it?
Basically I have a folder with a list of java files. I run javac program.java to compile and then java program. The one thing I have seen in these forums is about setting the classpath, but no specifics on what to set it to. Basically I have a folder with the source called java. The only subfolder there is org, the next subfolder is apache, next is commons, then httpcliet, and then all the actual java files with a few other folders with the java files in them. It gives examples in the folder src which is the parent of java. In src there is a folder called examples. The relevent import statements are:
import org.apache.commons.httpclient.HttpClient;
import org.apache.commons.httpclient.MultiThreadedHttpConnectionManager;
import org.apache.commons.httpclient.methods.GetMethod;These are all valid files under the folder system, yet it gives me the error : package org.apache.commons.httpclient does not exist for the first 2 and package org.apache.commons.httpclient.methods does not exist.
There are also errors resulting from it not recognizing the import statements. Can someone help me please?I had a choice between source and binary, if I
download the binary, should I put the jar file inthe
folder with the rest of my *.java files?You can, but I'd advise against it because it gets
messy and confusing.
Or do I have
to put the whole folder (with the API, liscense,
readme, etc. in it) in the same folder as MY codeor
do I just need the .jar file? You just need the jar file. Don't unpack the jar
file; the standard java libraries know how to deal
with a jar file just fine.
More-or-less standard practice would be to create a
directory hierarchy like this:
project_name/
project_name/lib/
project_name/src/
project_name/classes/
Put the jar files in project_name/lib. Put your java
source files (the ones that you're creating) into
src/, and when you compile, put the compiled class
files into classes/ (use the -d option to javac to do
that). When you compile and run, include both the
classes/ directory and the jar files (note: NOT the
lib/ directory, specify the individual .jar files) in
the classpath.So do I need the absolute path of the .jar file? If I were to put it in the same folder as my source could I just specify as
javac -classpath whateverjar.jar MyFile.java
or do I have to do javac -classpath C:\my folder\my other folder\etc\projectName\lib\whateverjar.jar MyFile.java?
Thanks -
SSL with third party certificate
Hi All,
I followed the configuration mentioned in the white paper
Oracle Forms Services 10g: Configuring Transport Layer Security with SSL An Oracle White Paper July 2005 (frm10gss.pdf). That is working fine.
I have a third party certificate (file format - .der, I got .cer from that).
With this certificate i need to configure the Application Server 10g. For this certificate i didn't created certificate request and sent to the third party.
In the steps motioned in the frm10gss.pdf where i have to make changes to include the third party certificate and not to consider the default oracle OCA certificate. Or with that Certificate how can i configure the SSL.
Any suggestions please…Hi All,
I followed the configuration mentioned in the white paper
Oracle Forms Services 10g: Configuring Transport Layer Security with SSL An Oracle White Paper July 2005 (frm10gss.pdf). That is working fine.
I have a third party certificate (file format - .der, I got .cer from that).
With this certificate i need to configure the Application Server 10g. For this certificate i didn't created certificate request and sent to the third party.
In the steps motioned in the frm10gss.pdf where i have to make changes to include the third party certificate and not to consider the default oracle OCA certificate. Or with that Certificate how can i configure the SSL.
Any suggestions please… -
Replace Self-Signed FAST Search Certificate with Third Party Certificate
We are trying to replace the Self-Signed FAST Search Certificate with Third Party Certificate in our SP 2010 environment. And are facing issues while enabling the SSL communication between the FAST servers and the corporate servers.
Our FAST search servers are in a different farm than that of the Corporate Servers.
The details of the certificate we received is as follows:
Issued to : FastSearchCert
Issued By: Issuer Name
Valid From: 4/21/2015 to 4/20/2017
We were able to successfully renew the certificate on the FAST Search Server by following the below steps:
1. Login to the Administrative and the Non-Administrative nodes
of the FAST server. Go to Windows Service and stop the FAST Search for SharePoint and the FAST Search for SharePoint Monitoring services in both the servers.
Follow the below steps in the Administrative Node followed by the Non-Administrative Node
2.
Install the certificate in the following paths in the certificate store:
“Certificates(Local Computer)\Personal”
“Certificates(Local Computer)\Trusted Root Certification Authorities”
3. Ensure that the user account configured for the “FAST Search Server 2010 for SharePoint” has access to the private key of the certificate.
4. Go the Administrative node of the FAST farm and follow the below steps:
Go to the certificate store.
Expand the Personal folder and then click the Certificates folder. Double-click the third party signed FAST certificate.
Open the Details tab and then click Thumbprint. Note down this thumbprint.
5. Next, open
Microsoft FAST Search Server 2010 for SharePoint with Administrator
Privileges.
6.
Navigate to the directory, “D:\FASTSearch\installer\scripts” and execute the below command to replace the current certificate with the newly created
third party signed FAST certificate.
.\ReplaceDefaultCertificate.ps1 -thumbprint "certificate thumbprint".
7. The FAST certificate was renewed successfully.
Once the certificate has been renewed successfully in both the nodes, follow the below step:
8. Start the FASTSearch for SharePoint and the FAST Search
for SharePoint Monitoring services in the administrator server.
Next, while enabling the SSL communication between the FAST servers and the other corporate servers, we follow the below steps:
1.
Copy the new certificate from any of the FAST servers to all the web-front end and application servers in the corporate farm, in order to enable SSL communication between these servers and the FAST farm.
2. Also, copy the script
‘SecureFASTSearchConnector.ps1’ from the location “%FASTSearchFolder%\installer\scripts” in the FAST servers
to the web-front end and application servers of the corporate farm.
3. Follow the below steps on each of the servers in the corporate farm:
Open ‘SharePoint 2010 Management Shell’ with administrator privileges and navigate to the directory in which
SecureFASTSearchConnector.ps1’ script is located.
And then, execute the below command:
.\SecureFASTSearchConnector.ps1 -certThumbprint "certificate thumbprint" –ssaName “FASTCibtebtSSA” –username “DOMAIN\SP_Farm”
Where,
-certThumbprint
- Thumbprint of the certificate
-ssaName – FAST Content SSA
-username – The account configured to run the SharePoint
Search Service
On execution of the above command, we receive an error message stating that the "Connection to the Content Distributor servername.corp.abc.org: 14391 could not be validated...instance of FAST search server backend is running"
Please help us resolve this issue. We have not been able to find the cause of the above error for a long time.
Any help is much appreciated.Your tip on exporting from eDir to locate a missing private key was very helpful. Here are my steps to renew an expired third party certificate when the private key, generated 30 months ago in my case, could not be located.
In iManager, browse the tree and locate the likely certificate object. The Attributes for the object show Subject Name = webmail.acme.com. Selected the certificate and exported to webmailcert.pfx.
Then, the openssl commands in TID 7004039, "How to convert a SSL PFX to a PEM file", were run against the .pfx file to create cert.pem, key.pem and server.key files.
TID 7015500, "How to determine if private key belongs to public key (certificate)", was followed to determine if the public key (downloaded from third party) and private key (just retrieved from iManager) match - they did - that is, the private key converted from webmailcert.pfx matches the downloaded certificate.
TID 7013103, "How to create a .pem File for SSL certificate Installations", was followed to manually create a server.pem file using openssl.
TID 7010584, "How to setup SSL Certificate for Apache", part labeled "Additional Information" was followed to modify /etc/apache2/vhosts.d/vhost-ssl.conf file. Server.pem file created above copied to /etc/apache2/ssl.crt/ and /etc/ssl/servercerts/ directories as specified in vhost-ssl.conf.
Restarted apache2.
www.digicert.com has an SSL Certificate Checker that can be used to verify the installation is successful. -
Install third party certificate on MAC os X
Hello,
I have installed leport 10.5.X on my machine. I am new bie for MAc and want to install intermediate certificate for my domain from Digicert. I have registered from Digicsert. Please help me to how can I install on the machine. I also need to create a new certificate but when I tried to add it shows an error message like this.
"There are no valid root or intermediate certificate authorities available to sigh certificates. Use the "create certificate Authority" option to create a certificate authority."
Can anybody please help me to what should be the next step.
And how can I install third party certificate.
Thanks in advance.There is a product called VolumeWorks that is supposed to do this. I looked at the demo, but I could not get it to see the extra space so I ended up backing it all up and erasing the Raid and doing a block copy with Carbon Copy Cloner.
-
When will CDN on azure support SSL for custom domain. Its almost so long we are discussing and facing a huge impact on our sales and support queries. Our entire application sits on azure. We need a solution ASAP. It has been a long wait.
hi,
Thanks for posting!
As far as I know, It may be not supported that you use the Third party certificate to custom CDN domain. You could vote this feature request on this link (http://feedback.windowsazure.com/forums/169397-cdn/suggestions/1332683-access-to-cdn-over-ssl-https
). Also, I will report this issue.
Thanks.
Regards,
Will
We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
Click
HERE to participate the survey. -
WLC526 third party certificate?
Hi!
Is it possible to install a third party certificate on the WLC526 Controller?
Would be great for Web Authentication for my Guest Wlan!
Thankx
DavidHi,
If the certificate cannot be used for SQL Server and hence will not be visible in SQL Configuration manager. Check the validity of the installed certificate. It may not has the correct DNS name.
I suggest you request a new third party certificate from the vendor with the correct DNS name. Install it on SQL Server environment, then you should see certificate form the configuration manager dropdown box.
Thanks.
Tracy Cai
TechNet Community Support -
Importing third party XML files into form-based publishing
Hi,
I want to import third party XML files into form-based publishing. My problem is that when I open the files, they are presented as normal XML files.
The 'type' property is not set to "form-based publishing". That's the reason no form is linked to the XML file.
Is there a way to change the value of this 'type' property? Then I can set it to "form-based publishing".
Message was edited by: E. van der PalenHi,
You should take into account two things:
1. XML Repository filter
System Administration-System Configuration-KM-CM-Repository Filters-choose XML Forms Repository Filter
edit it and add your repository.
After that you have to restart it.
2. Resource Type.
You should modify cm_resourcetype property to set form-based publishing.
You could edit this xml file using form builder and then set this parameter.
Patricio.
Maybe you are looking for
-
How can I share address lists between two iCloud users
My daughter and I have two different icloud accounts. We are able to share certain calendars, but I would like also to share address lists/groups. Is there a way to do this? I think you could "subscribe" to another Mobile Me user, but how is this
-
My Photoshop CS is no longer working and I have not changed any configurations.
I have not changed my computer configurations but it states that I have and now is stating I need to activate my Photoshop. When I do so, it leads me to a page that I try and then it gives me an error message about the server not being available. I
-
What's this new thing I'm seeing in my emails which have pictures attached?
I sent myself some pictures from one email to another but when I opened the email under each photo the was this box under it that had this... ATT00003 and under that it says 23bytes. I have not noticed this before iOS 6. Any one have an idea?
-
Dynamic User for Receiver RFC adapter
Hi, I have a soap to rfc scenario. Any solution to use PI login user as RFC user to connect SAP backend? Thanks
-
Can't download safari 4.0.3. with Mac 10.5.4. help!
I haven't been able to use itunes for a week. I have already updated my Mac twice but still says I need safari 4 which I can't download because I have 10.5.4. This is ridiculous. Has anyone else with MacBook been able to get past this issue?? I asked