New certificate installed, /LDAPv3/127.0.0.1 unavailable, 10.6.5 Help?

I am seriously worried. I used to have the following setup:
- GoDaddy signed cert for several services on domain name cert.bar.nl, used for mail authentication etc.
- self-signed cert for Open DIrectory on domain name main.bar.nl
I have done the following:
1. Created a new self-signed cert for main.bar.nl in order for it to be signed (I could not use the old one as it had insufficient bits)
2. Had this signed succesfully
3. Installed this as the signed cert in Server Admin
4. Tested it by using it for secure https, worked fine
5. Then removed the old self-signed cert and selected the new signed cert as cert for Open Directory
Result: clients cannot mount their afp: directories for home syncing and what is more important, I cannot get to the /LDAPv3/127.0.0.1 directory with all the network users anymore. If I open Workspace Manager, I get Local/Default, but trying to move to my network directory fails. WM says: "Unable to open the requested mode" followed by "The node /LDAPv3/127.0.0.1 couldn’t be opened because an unexpected error of type -14002 occurred."
Help? How do I restablish a connection to my network directory? On client computers, I can still log in, but probably because stuff has been cached and I am deadly afraid I will lose login of network accounts (all acocunts are mobile accounts with synced portable home directories).

By restoring /private/etc/certificates and /private/etc/openldap from my CrashPlan backup, I have been able to restore working access to my /LDAPv3/127.0.0.1 directory (network users). I have two problems left:
- Server Admin shows the new certificate for main.bar.nl and in Open DIrectory, Server Admin shows Use SSL, but does not show a selected certificate. Where does Server Admin keep its knowledge about certificates? Or how do I repair Server Admin's knowledge about certificates?
- Selecting the newly signed certificate for use in Open DIrectory recreates the problem. So, I have a nicely signed certificate for main.bar.nl, but as soon as I use it, access to /LDAPv3/127.0.0.1 is lost. What next?

Similar Messages

  • Lost federation connections after installing new certificate

    After installing a new NIC for the egde external connection and new GoDaddy 10-slot UCC cert on my edge server and Forefront TMG reverse proxy, I have lost the ability to connect to my federated partners.  Snooper logs seem to indicate that the
    certificate is not being accepted.  Test-CsFederatedPartner returns the message, "This machine does not have any assigned certificate."  Running the Lync Deployment Wizard on the edge shows that it definitely does have a certificate.  Get-CsCertificate,
    Test-CsComputer, and Test-CsCertificateConfiguration all show the new certificate is in place.  Digicert's online certificate check has no problem finding the edge server and has verified that the cert is functional.  This edge server was running
    perfectly for over a year.
    I'm stumped.  Thanks in advance.

    Hi,CJADuva,
    Did all your other external access such as external user login and download address book or meeting content work normally?Just the federation broken?
    What the SN and SAN entries of the new GoDaddy UCC certificate?Do they meet the external Edge certificate requirements?Check the following links for Edge certificate requirements
    http://technet.microsoft.com/en-us/library/gg398920.aspx
    http://technet.microsoft.com/en-us/library/gg398519.aspx
    If all are ok,please ask your federated partner to check if the Godaddy CA is in their trust CA list,also I remember that Godaddy always has intermediate certificate,please check if you and your partner has installed it too.
    Check
    http://support.godaddy.com/help/article/869/how-do-i-install-an-intermediate-certificate for more details about installing intermediate cert.
    Regards,
    Sharon
    Sharon Shen
    TechNet Community Support
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question.

  • Nokia N82 and Microsoft certificate install

    I got my N82 after using Windows Mobile for over 6 years I decided to get a phone that does email not the otherway round. I install MfE or Mail for Exchange and started sync'ng and was told to install a certificate. After spending the best part of a week trying to get the certificate installed I am stuck. The best resource I have found online so far is http://www.redelijkheid.com/symcaimport/ which allows you to upload a .cer file and then download it to your file. All the other sites talk about modify web sites and playing with the MIME, etc. That just disable the Exchange Sync default website since you need to overwrite the SSL port. Cannot use OpenSSL is I run Windows XP not linux. I see a N95 user had the same problem. If you copy the cer file, even if it is renamed it does not open on the phone if you export a .p12 it wants you to enter a "new key store password". I know with my last phone an imate I had to get a certificate install package, is there any such thing.
    Anyone out there got any ideas or pointers
    Unhappy email user, happy phone user

    Might not help a great deal but you can use OpenSSL on Windows, but you'll need to compile it. How you do that, I haven't got a clue as I normally use Linux for that kind of thing my self.
    Owned: Nokia 3510i, Nokia 3120, Nokia 6230i, Nokia 6233, Nokia N73, Nokia N82.
    Current: Nokia N900!

  • Modify installation procedure for AIR apps with new certificates?

    Hey all,
    My company just got a signed certificate for the AIR application I've been working on.  Unfortunately, when users try to install this new version, they get the following error message now:
    I understand why this is: The application doesn't recognize the one with the old certificate and won't forcibly override it.
    (Source: http://mxbase.blogspot.com/2008/04/air-update-and-certificate.html)
    My boss wants me to find a way to make the transition between certificates seamless (ie. just reinstall over the old one as if they both had the same certificate - no uninstall, no save to new location, no unusual tasks for the users).  Is this possible?  If so, how?  I know it's a heck of a question to ask 
    Thanks so much, all!
    -Katherine

    You should never let your certificate expire before renewing it or getting a new one.
    Did you get a new certificate or renew the old one?
    If new, then your users must uninstall the old version and then install your new version. Any data your apps stores in the EncryptedLocalStore will be inaccessible. Any files your application has stored in the application storage directory will have to be copied to the new storage directory by the updated app.
    If you renewed the certificate, then presumably you are getting this error because the Certificate Authority has changed their own certificates used to sign their issued certs. If this is the case, they might (for some thousands of dollars) be willing to perform a key ceremony to bring the old certificate out of retirement and reissue your new certificate so that it has the same identity as the old one.

  • Exchange + new certificate

    Hi,
    till today was all perfect ! our Ipads was able to connect our exchange and synch emails
    the only "strange" issue was that instead the domain (ex webmail.mydomain.com) I need to use the ip address.
    today I've got the new ssl certificate and after the installation , the ipad stop to work... it's impossible to connect to the server. I've also tryed to install manually the certificate on the ipad.. but nothing is changed.
    any idea ?
    tnx Massimo

    Hi Goran,
    Yes I already delete it few time. the only thing that is changed in IIS is the SSL certificate.
    When I created the account I also tryed to use a wrong password and during the save of the configuration I got an error and I need to force the save "this account is not able to send e receave email do you want to save... etc " ... but If I use the right login and password the saving is quick and without any prompt message.
    but when I try to check my email I get the message that the server is impossible to contact.. how is it possible ??? It's seems that during configuration it can contact the server and check login and password but after no...
    I also tryed to configure the same account on a Iphone4 and I saw in a prompt message detail the wrong (old) certificate !??!?!
    but using Ipad browser or pc browser or online tool (from verysign) the installation is right ...
    it seems that ipad and iphone are not able to get the new certificate but they still continue to get the old
    I've also reset the Ipad without result.
    thank for help

  • New Certificate/Password Prompt

    We have been using the Palm Treo 700wx in our office for over 1 year. To this point, no problems.
    Our OWA/Exchange/OMA certificates were due to expire, so 1 week prior, I renewed the certificate..then updated the appropriate area's within the organization with the new certificate.
    OWA/OMA etc..work perfectly using the new certificate. (Which is essentially the same exact cert as it was, just renewed..)
    I went in, removed the old certs and installed the new cert from each Treo, tested..seemed to work just fine with the new cert.
    Finally the expiration date of the original certificate arrived and with it, an error message on each Treo when trying to sync: Certificate expired, check time and date..etc...common error message for either an expired cert or the date and time being wrong...after a few hours of investigation, including a few phone calls to palm/sprint "tech support" I was told (and read in various forums) that this problem is common  with Windows Mobile when using your own certificates and that although I had deleted the original certificate - It wasn't actually deleted - as the cert gets embedded to the phones ROM and the only way to truly rid the original cert is to do a hard reset and reconfigure....sigh...So I go through the process on each phone.
    Hard reset, re-import the new certificate - and sure enough it works...However with this....solution.. I have a new issue. About 75% of the phones now have an issue where it doesn't sync without the end user forcing the sync on their end and often when they do, they are prompted to give their password (network credentials to access our network/exchange). And Yes, Save Password is absolutely checked on all of the phones in question. Once they supply their password, the phone syncs as normal for a short duration...then eventually they are again prompted for their password...This goes on throughout each day, meanwhile about 25% of the phones are working as normal?? No server settings were ever changed what-so-ever - the only thing changed or updated is the renewed certificate. On the phone side, the only changes were hard reset to factory defaults - then configured using the new certificate. Has anyone out there run into a similar scenario and is/was there any resolution to this issue???
    Post relates to: Treo 700wx (Sprint)

    We have been using the Palm Treo 700wx in our office for over 1 year. To this point, no problems.
    Our OWA/Exchange/OMA certificates were due to expire, so 1 week prior, I renewed the certificate..then updated the appropriate area's within the organization with the new certificate.
    OWA/OMA etc..work perfectly using the new certificate. (Which is essentially the same exact cert as it was, just renewed..)
    I went in, removed the old certs and installed the new cert from each Treo, tested..seemed to work just fine with the new cert.
    Finally the expiration date of the original certificate arrived and with it, an error message on each Treo when trying to sync: Certificate expired, check time and date..etc...common error message for either an expired cert or the date and time being wrong...after a few hours of investigation, including a few phone calls to palm/sprint "tech support" I was told (and read in various forums) that this problem is common  with Windows Mobile when using your own certificates and that although I had deleted the original certificate - It wasn't actually deleted - as the cert gets embedded to the phones ROM and the only way to truly rid the original cert is to do a hard reset and reconfigure....sigh...So I go through the process on each phone.
    Hard reset, re-import the new certificate - and sure enough it works...However with this....solution.. I have a new issue. About 75% of the phones now have an issue where it doesn't sync without the end user forcing the sync on their end and often when they do, they are prompted to give their password (network credentials to access our network/exchange). And Yes, Save Password is absolutely checked on all of the phones in question. Once they supply their password, the phone syncs as normal for a short duration...then eventually they are again prompted for their password...This goes on throughout each day, meanwhile about 25% of the phones are working as normal?? No server settings were ever changed what-so-ever - the only thing changed or updated is the renewed certificate. On the phone side, the only changes were hard reset to factory defaults - then configured using the new certificate. Has anyone out there run into a similar scenario and is/was there any resolution to this issue???
    Post relates to: Treo 700wx (Sprint)

  • New Infinity install and Philips Smart TV

    Any ideas on how to resolve my connection issue. I have a Philips smart TV which until I had Infinity and the new HH3 installed on Thurs(7th Feb.) connected without any issues with my previous supplier's BB (Sky).  Tv is connected and finding net ok but cant/wont connect to Smart Tv.  I've enabled Port clamping as advised in other posts but still no joy.  Any other suggestions appreciated.  I pretty sure its not a TV issue as It worked no problems pre Infinity and TV is as up to date as you can get,Software update etc.
    Thanks
    Solved!
    Go to Solution.

    Hi,
    I have the same problem with a Philips 40pfl8605 and a home hub 3 (but not the infinity package). the tv connects to the router, either wirelessly or via ethernet, but will not load Net TV. I get an error message which says 'Philips server not found. Try again later). 
    Keith, I'm on my home network now but you're link wouldn't open a few minutes ago. I can't work out how to message you directly on this forum, but if you can send me the content of that link on the thread, i'd be grateful. I'm pretty sure this problem stems from the router as the Net TV has connected in the past, when I've had a netgear router. Philips have been useless and after running through standard checklists such as clearing the Net TV memory, reinstalling software (which is up-to-date) etc, simply advised to send the (3yr-old) tv for repair. 
    Looking forward to hearing from you.

  • Can the new pre installed apps in iPad 2. Like garage band, iMovie be sync back to i tune, and then sync these new apps from ipad2 to the old iPad 1?

    Can the new pre installed apps in iPad 2. Like garage band, iMovie be sync back to i tune, and then sync these new apps from ipad2 to the old iPad 1?

    GB and iMovie pre installed?
    http://www.apple.com/ipad/built-in-apps/
    Click: Browser All Built In Apps
    iMovie and GB must be purchased.
    If you have installed GB and iMovie on the iPad 1 and synced using iTunes, just sync the those apps to the newer iPad with iTunes. No re purchase necessary with the same iTunes account.

  • How do I get the old Apple ID off of my iPhone and the new one installed?

    I got a MacBook Pro and decided to create a new Apple ID different from the one I previously had. How do I get the old Apple ID off my iPhone and the new one installed?

    When I tried this, my music stayed the same whereas my new iTunes has only about half the music it used to.  How can I get all the music to clear out so that it can sync my new music to it.  Simply connecting it to the MacBook Pro and pressing Sync has not worked.

  • Open Directory Server appears as /LDAPv3/127.0.0.1, not as /LDAPv3/FQDN

    I am running Mac OS X Server 10.4.7 and when I setup my Open Directory Master it shows in Directory Access Utility and Workgroup Manager as /LDAPv3/127.0.0.1.
    This not make sense since a nslookup anwers correctly for IP address and Hostname. So, I think it would shows as /LDAPv3/FQDN
    If I change the field "Server Name or IP Address" in LDAPv3 section of Directory Access Utility to the FDQN, Workgroup Manager shows /LDAPv3/FQDN and works perfectly, but if I try to create an Open Directory Replica in another server, I receive a message "Unable to Authenticate on Server as Directory Admin"

    Thanks for your answer Ralph!
    Really I get my other server promoted to an OD Replica when my OD Master appears as /LDAPv3/127.0.0.1, but I was in doubt about this when I go to the Replica's WGM Sharing pane to set User's folder as an Automount Point in /LDAPv3 Directory because it shows as /LDAPv3/127.0.0.1
    Maybe I am wrong, but in the Replica's server this will point to the localhost directory. This assumption is correct?

  • My hard drive crashed on my macbook pro and I had a new one installed and they were unable to get my pictures off of it. Is there anyone who could help? I'm going to lose all my memories of my kids! I got my old hard drive

    My hard drive crashed on my macbook pro so i had a new one installed and they couldn't get my pictures off. I dont want to lose all my memories! They gave me back my old hard drive. Is there anyone that could help me?

    I think how you understand the value of having backups. All you can do is:
    General File Recovery
    If you stop using the drive it's possible to recover deleted files that have not been overwritten by using recovery software such as MAC Data Recovery, Data Rescue II, File Salvage or TechTool Pro.  Each of the preceding come on bootable CDs to enable usage without risk of writing more data to the hard drive.  Two free alternatives are Disk Drill and TestDisk.  Look for them and demos at MacUpdate or CNET Downloads. Recovery software usually provide trial versions that enable you to determine if the software would help before actually paying for it. Beyond this or if the drive has completely failed, then you would need to send the drive to a recovery service which is very expensive.
    The longer the hard drive remains in use and data are written to it, the greater the risk your deleted files will be overwritten.
    Also visit The XLab FAQs and read the FAQ on Data Recovery.
    You will need an external enclosure for the old drive so you can connect it to the computer in order to try the recovery software before you buy it. But if they don't work then you will need to send the drive to a recovery service such as Drive Savers.

  • I upgraded my iBook G4 from 384MBytes to 640Mbytes and upgraded from Tiger to Leopard. After a few weeks the HDD failed. New Leopard install reports: "insufficient memory". I need Tiger install disks so I can install

    I upgraded my iBook G4 from 384MBytes to 640Mbytes and upgraded from Tiger to Leopard.
    After a few weeks the HDD failed. I bought a new disk, installed it and trued to install Leopard, but the  install fails reporting "insufficient memory".
    I assume the installation requires more memory than the OS actually needs to be able to run.
    I need Tiger install CD/DVD so I can install Tiger first and then upgrade to Leopard.

    Call Apple Customer Support 1-800-767-2775, provide the Serial Number and specifications of the Mac, and for a reasonable fee, they will supply a replacement set of system discs (if available).
    The discs will be for the original version of the OS that was pre-installed when the Mac was manufactured.
    You need much more RAM than that.
    Leopard system requirements:
    http://support.apple.com/kb/SP517

  • Tried to update iPod, failed, no new drivers installed. Now iPod does not show in my computer or in iTunes.

    Anyone know how I can update/unbrick this iPod? It's useless. It's stuck on the screen that says connect to iTunes. iTunes doesn't know it's there. My computer doesn't know it's there. It's not the USB port.
    Please don't direct me here - http://support.apple.com/kb/HT1808 - already tried, no results.
    Last time it was a missing driver for iTunes but iTunes says nothing new is needed. Help appreciated.

    Let me try this again. My computer said my iPod needed an update. I clicked ok. iTunes said it was doing the update. I browsed the internet. I came back to it after it was done, and it said update failed, no new drivers installed. Now my iPod touch is a brick. I cannot use it for anything. You know that screen that shows the usb cable, a white arrow, and iTunes? It's stuck there. No amount of pushing the sleep/wake button and home button will convince it to go to any other screen. When I go to 'My Computer', it does not recognize that there is anything there. It is not the USB port. Everything was fine until the update tried and failed.
    I am not installing iTunes (piece of crap software that it is) on the other computer in my apartment.
    I have exhausted the articles that sort of go with the problems I am having. They all assume a non brick iPod. Mine is a brick and therefore those articles, including the one you linked, are not relevant.
    Not meaning to be rude, but I came into this not caring much for Apple's business model. I've had my iPod for .. a week? Maybe two, and nothing I've seen has convinced me to feel otherwise. Apple's products are supposed to just work. I am not finding that to be the case. Anyone with anything helpful please?

  • HT3917 My apple wireless keyboard is not working after new batteries installed

    My apple wireless keyboard is not working after new batteries installed.

    Do you get a steady green light to say there is a connection.    If not, are the batteries the right way round.   Do you have a monitor to tell the batteries strength. Is there a reading.   Are the batteries good quality ones, Duracell, Energiser or Apple rechargeables.

  • My hard drive crashed and I now have a new one installed. I have lost my purchased Adobe Creative Suite 6 Design Standard MAC OS. I have the reciept and product; can I reinstall it into the computer?

    My hard drive crashed and I now have a new one installed. I have lost my purchased Adobe Creative Suite 6 Design Standard MAC OS. I have the receipt and product; can I reinstall it into the computer?

    Download CS6 products
    Mylenium

Maybe you are looking for