Unable to Access CSACS 5.3 Web Interface...

Hi Everyone,
I wanted to note an issue I ran into today with our MS Windows 7 workstations and 2008 servers being unable to access the web management interface on our instance of ACS 5.3 and its solution, which is outlined below:
###      The Problem      ###
When I tried accessing the web management interface on our ACS 5.3 appliance, the browser was unable to connect.  NMS applications showed that the device was up and I was able access it via SSH.  I then tried connecting to 443 via telnet on my workstation and was successful in establishing a connection.  I proceeded to issue the "show application status acs" command showed all associated processes running.  I had a co-worker attempt to access it and he ran into the same issue.  I then proceeded to restart the ACS application by stopping and starting the associated processes.  After the processes were back up, attempts to connect to the web management interface still failed.  I then proceeded to reboot the appliance.  Again, after the applicance and processes were back up, attempts to connect continued to fail.  As a last ditch effort I used a portable version of Firefox to connect and was then successfully able to connect.
###       The Source        ###
After additional troubleshooting, it was discovered that the MS Internet Explorer patch associated with MS Security Advisory 2661254 just so happened to be the culprit.  This restricts the use of certificates with RSA keys less than 1024 bits in length.  The default management certificate just so happens to be 512 bits in length.
###          The Fix           ###
Using FireFox, I navigated to System Administration > Configuration > Local Server Certificates > Local Certificates.  I then proceeded to add a certificate in the following steps:
Select Generate Self Signed Certificate & click next
Populate the Certifcate Subject field with the appropriate DN information of the ACS server.
Change the key length to 1024 or above.
Check "Management Interface:  Used to authenticate the web server (GUI).
Check "Replace Certificate".
Click Finish.
The ACS server should then generate the new certifcate, replace the existing management certificate, and restart the ACS processes.  After everything is back up, you shouldn't have any issues in accessing the web interface.
Cheers,
Dan

Hello Dan,
Thank you for trying to share the information you have.
Note please if you want to share information you can post a document, not a discussion.
You can convert this discussion into a document from the right pane menu.
Greetings,
Amjad
Rating useful replies is more useful than saying "Thank you"

Similar Messages

  • Unable to access to Collaborative Views Web Interface

    Hello,
    When I try to access to the Collaborative Views Web Interface through the URL
    http://<URL of your J2EE server>/cviews/views/init.do
    I have the following error message :
    ISA Framework: Internal Error
    No XCM application configuration has been passed and there is no default XCM application configuration defined. Check XCM configuration
    I looked at the XCM Adminitration Web Interface, but I do not know what to configure to make the Collaborative Views Web Interface available...
    Any ideas ?

    Hi Sebastien,
    you have to access the following link:
    http://<host>:<port>/cviews/admin/xcm/init.do
    The first thing is to crete a default configuration based on the possible templates. After that you need to define a connection the Backend - JCo connection. after that save the configuration and restart the application. try again.
    In the XCM area you can get some more information on what needs to be maintained by clicking on the "i" icons next to each field.
    Hope this will help you.
    Cheers
    Borislav

  • Unable to access Workspace through Apache web server

    Hi,
    I have configured Hyperion 9.3.1. products in windows.
    I am getting the following error message when trying to access Workspace through Apache web server(port 19000). But, able to access through Weblogic Application server(port 45000).
    please assist me in resolving this issue.
    Internal Server Error
    The server encountered an internal error or misconfiguration and was unable to complete your request.
    Please contact the server administrator, [email protected] and inform them of the time the error occurred, and anything you might have done that may have caused the error.
    More information about this error may be available in the server error log.
    Apache/2.0.63 (Win32) mod_jk/1.2.8 Server at nasbydapp04 Port 19000
    Thanks,
    Siva

    I re-configured the BIPlus components and even now, i am unable to access workspace through Apache web server.
    But now, i am getting a different error
    Error:
    HTTP 404 - File not found
    Internet Explorer
    Can anyone help me in resolving this issue.
    I have updated httpd.conf and HYSL-Weblogic.conf file in Apache server.

  • Unable to access calendar, because the web service is configured incorrectly

    When attempting to access my web based calender I recieve the following error, "Unable to access calendar, because the web service is configured incorrectly." I have both the web service and iCal server configured to use SSL.
    Thanks for any help

    I have the same problem, with a temporary solution :
    http://forums.macosxhints.com/showthread.php?t=111059
    In the Server Admin - iCal Server Settings page there's a place where you specify the ports to be used, 8008 without SSL and 8443 (? out of my memory, not sure) for SSL.
    The issue was caused because left of the SSL port I selected "redirect" instead of "use".
    After I changed that it worked right away.
    Laurent

  • Accessing Email (inbox) via web interface

    Hi All.
    I am testing functionality of Oracle Beehive.
    I installed Beehive 1.4.3.0 + Beekeeper 1.4.3.0 on windows 2003. Is there a possibility for a user to access email inbox, address book, etc. via web page similarly as it is in Zimbra? If yes how can I access it? (which url, port).
    Regards
    Groxy

    Hi,
    If you had 3Gb or more RAM in the machine where you installed Beehive server, the Zimbra web interface would have been configured automatically in 1.4.3. It'll be at http://server:port/zimbra. Where 'server' is the beehive server and port is probably 7777 if there was nothing else on the machine consuming that port when you installed.
    Richard

  • Unable to access the Router's Web-Based Setup Page

    Hey, I found a little problem when I tried to change the configurartions to my Linksys WRT54GS ver- 6.0 router. Problem is that I can not acces to setup, nor can I connect to Internet trough wire. Can somebody help me with my problem?
    Pasi

    To view the router's web pages:
    You do not need an Internet connection. The router's "web pages" are built into the router.
    Use Internet Explorer, it usually works.
    JavaScript must be enabled.
    Use a computer that is wired to the router.
    In the non-working computer, temporarily turn off your software firewall.
    Point your browser to 192.168.1.1 , then login to your router. Your user name should be left blank. Your password is "admin" (with no quotes), unless you changed it.
    If you are using Zone Alarm, right click on the ZA icon in the system tray (lower right corner of screen) and then click "Shutdown ZoneAlarm", and see if this fixes your problem. If this does not work, try the following with Zone Alarm: Open the ZAISS control center, go to Privacy, then temporarily turn off Ad Blocking and Cookie Control, and see if that fixes your problem.
    If you are using Noton Internet Security with the Add-on Pack, be sure to turn off the Pop-up Blocker, and the Ad blocker. Some users have reported that they needed to uninstall the entire Norton Add-on Pack.
    If you cannot get anything at 192.168.1.1 then perhaps this is not your router's address. Go to "Start" > All Programs > Accessories > Command Prompt.
    A black DOS box will appear. Type in "ipconfig" (with no quotes), then hit the Enter key. Look at the "Default Gateway". Is it 192.168.1.1 ? Point your browser to the "Default Gateway", then login to your router.
    If the above fails, disconnect your modem from the router, and try again. If this corrects your problem, then most likely you have a "modem-router" rather than an ordinary modem. Report back with this problem, and also state the make and exact model number of your modem (not the router).
    If all of the above fails, power down your entire system, unplug it from the wall, wait one minute, then power up and try again.
    If all of the above tips fail, then reset the router to factory defaults: Power down the router and disconnect all wires from it. Wait one minute. Power up the router, allow it to fully boot (1-2 minutes), then press and hold the reset button for 30 seconds, then release the button and allow the router to reset and reboot ( 2-3 minutes). Power down router. Wait one minute. Connect one computer, by wire, to a LAN port on the router. Boot up system. It should work.
    If the reset does not fix your system, then you need to download and install (or re-install) the latest firmware for your router. After the firmware upgrade, you must reset the router to factory defaults, then setup the router again from scratch. If you saved a router configuration file, DO NOT use it.

  • ACE unable to access through web browser.

    Hi Team,
    We have 4710 ACE in our network and currently we are using software version A3 2.0.
    Currently we are not able to access the ACE through web interface but Telnet is happening properly. Connection is establing while we are doing the telnet to ACE through port 80 and port 443. Kindly suggest what will be the Issue? Please find the below dummy configuration.
    resource-class SLB_STICKY
      limit-resource all minimum 0.00 maximum unlimited
      limit-resource sticky minimum 10.00 maximum equal-to-min
    access-list ANY_Traffic_Permit line 8 extended permit ip any any
    access-list ANY_Traffic_Permit line 16 extended permit icmp any any
    class-map type management match-any CM_Remote_MGMT
      description *** Class-Map defined the permitted Protocol list for Remote Management ***
      201 match protocol icmp any
      202 match protocol telnet any
      203 match protocol http any
      204 match protocol https any
      205 match protocol snmp any
    policy-map type management first-match PM_Remote_MGMT
      description *** Policy-Map defined the permitted Protocol list for Remote Management ***
      class CM_Remote_MGMT
        permit
    interface vlan 60
      ip address 10.160.7.3 255.255.255.0
      alias 10.160.7.2 255.255.255.0
      peer ip address 10.160.7.4 255.255.255.0
      no normalization
      no icmp-guard
      access-group input ANY_Traffic_Permit
      access-group output ANY_Traffic_Permit
      service-policy input PM_Remote_MGMT
      no shutdown
    Thanks in advance..
    Regards,
    Ranjith

    Hi Ranjith,
    I dont see any problem with the config as per the doc.
    http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA3_1_0/configuration/quick/guide/setup.html#wp1010367
    What browser are you using? Did you atleast get a message to accept the SSL certificate as trusted when you access https://10.160.7.3
    Regards,
    Siva

  • Unable to Access Internet Despite Adapter Showing "Connected".

    Hi, I have a Lenovo "G"-Series notebook, Type 4446-38U which has suddenly stopped allowing me to access my internet connections.  The PC is only about a month old.  It is running XP Professional. 
    I have three connection options:  1) dial-up (using an onboard HDAudio Soft Data Fax Modem with Smart CP); 2) ethernet or Local Area Connection (using an onboard Broadcom Netlink Fast Ethernet); and 3) wireless (using an onboard Intel WiFi Link 5100 AGN) -- none of these components are showing that they have conflicts/problems in the System Properties/Device Manager. 
    At my home, which is located in a rural area where I can only get dial-up, I tried checking my e-mail last week (with Mozilla Thunderbird), but received an error notice stating that the e-mail server could not be found; it was the same issue, when I tried to get Norton virus updates (Internet Security 2009), XP updates on the Microsoft website (using Microsoft Updates with Internet Explorer), and simply accessing the web (using Mozilla Firefox) -- i.e., "Server Not Found."  The odd thing is that I can not only hear the connection being made by the modem, but can also see that the device is 'Connected', when I check the connection in Control Panel/Network Connections.  The following day at my office, I checked the other connection options (ethernet & WiFi), and found that I had the same problem -- i.e., they were shown as "Connected" in Control Panel/Network Connections, but I was unable to access anything on the web (e.g., e-mail, Google, virus/Microsoft updates, etc.).  It's as if there is something blocking the internet connection to these programmes/utilities. 
    When I ran the Microsoft Networking Troubleshooter ('Diagnose Network Configuration & Run Automated Networking Tests), all the Network Adapters were shown as having passed.  Ditto, when I ran the "Test a TCP/IP Configuration Using the Ping Command" -- pinging 127.0.0.1, the results showed 4 packets sent and 4 received.
    I spent several hours on the phone with Lenovo Tech Support to no avail, and their instruction that I uninstall Norton Internet Security made no difference either.  When they instructed me to open a Command Prompt and ping 192.168.1.1, the results showed that there were 4 packets sent and 4 received.  When I was instructed to ping the IP Address for the wireless adapter, the results showed 4 packets send and 4 received.  When I was instructed to ping www.google.com, the results showed that the ping request could not find the host www.google.com.  Lenovo Tech Support stated that there was nothing further they could do, and that I needed to use a utility to set everything back to factory specs (i.e., have a utility programme erase everything on the hard drive and reinstall XP ... and even then I was told that there was no guarantee that would fix things, meaning that the PC would then have to be sent into their repair depot).  Before I do this, I was hoping that someone here might know as to what's going on with my connection problems and how it could be fixed, without having to erase everything.
    I would appreciate any insight or advice anyone might have.  Thanks so much!
    ~ Jack

    I did do a complete uninstall of Norton (i.e., didn't save any of the settings), but that didn't resolve the connection problem.  I also turned off Microsoft's firewall as well, once Norton was uninstalled (it had been turned off, when Norton was installed, and once Norton was uninstalled, MS firewall defaulted back to an on/active status).
    I also forgot to mention in my initial description of the problem and actions taken thus far to try and correct it, that I additionally tried the "ping" procedure described in paragraph five above in Windows Safe Mode with Networking, but was still unable to connect to the internet.

  • Web interface security

    Hallo,
    how can I restrict access even in the web interface ? Once you're in the console anyone can access .
    Is there any way to request credentials from the web interface ?
    Thanks and regards

    Hi,
    Since I/O Analyzer is still experimental, currently there is no authentication enforced. Thus we highly discourage running this virtual appliance in a public-accessible network. Once I/O Analyzer becomes a more mature product, we might eventually integrate with VC and rely on VC authentication. However, there is no timeline on when this could be done in the short term.
    Thanks,
    Chien-Chia Chen

  • Setting up a password for a switch web interface?

    Hi,
    I am trying to figure out how to set up a username/password for this switch I have.
    it is a: Cisco WS-C2924M-XL
    It seems to be easy but I couldn't find out how to do it so far.
    Any help would be appreciated.. i just started working with this. thanks!

    Hi!
    Are you trying to enable and set username/password for accessing switch through the web-interface? I hope I understood you correctly.
    Firstly you need to enable the switch for web-interface.
    Enter this command --> ip http-server
    Then you can login using the username [admin] and the enable password.
    If you want to set some other username for this purpose, then enter this command --> username
    Then you can login using the username and the enable password. By default only level 15 access is enabled for the web-interface.
    For a lil more have a look at the following URL --> http://www.cisco.com/en/US/tech/tk59/technologies_configuration_example09186a0080178a51.shtml#local
    Hope this helps...
    Regards,
    AbhisheK
    Please rate all helpful posts!!!

  • What is the ir3245 default user and password for the web interface?

    I want to access our ir3245 via web interface ... need to try the default name/password.  If that doesn't
    work I need to know how to reset it to factory default so that it will work.
    Thanks for your help.
    Richard

    Hi Richard, thanks for posting.  Canon does not provide direct support for imageRUNNER series products, but your dealer will be able to help you!  If you don't have a dealer, please call us at 1-800-OKCANON (652-2666) and we will be happy to provide dealers who are in your area.

  • Unable to access WEB UI of WiSM2

    Bear with me as this is my first install of a 6500 and WiSM module.
    The backgroud is that we are small, but management used to be in networking and basically forced the the purchase of a 6509E.  Most of my experience is with 3560X and 2950 switches.
    I have followed the basic deployment guide here:http://www.cisco.com/c/en/us/support/docs/interfaces-modules/catalyst-6500-series-7600-series-wireless-services-module-wism/112968-wism2-deploy-guide-00.html.  My problem is that I have a flat network (see why I didn't want a 6500) so the management network and the production network is on VLAN 1.  Yes I know how bad this is, but apparently wireless is more important than adhering to good security practices.
    My problem is I am unable to access the Web UI of the controller.  I am however able to ping the address for the management IP.  I will give as much output as I can think would be helpful right now (and more if needed), but any assistance I can get would be appreciated.
    #show module
    Mod Ports Card Type                              Model              Serial No.
      2    4  WiSM 2 WLAN Service Module             WS-SVC-WISM2-K9    SAL172579DM
      6    5  Supervisor Engine 2T 10GE w/ CTS (Acti VS-SUP2T-10G       SAL1706YCQJ
    Mod MAC addresses                       Hw    Fw           Sw           Status
      2  30f7.0d0b.9820 to 30f7.0d0b.982f   1.1   12.2(18r)S1  15.1(1)SY1   Ok
      6  ccef.4838.97d5 to ccef.4838.97dc   1.4   12.2(50r)SYS 15.1(1)SY1   Ok
    Mod  Sub-Module                  Model              Serial       Hw     Status
      6  Policy Feature Card 4       VS-F6K-PFC4        SAL17299W2L  2.1    Ok
      6  CPU Daughterboard           VS-F6K-MSFC5       SAL1706YBTQ  1.5    Ok
    Mod  Online Diag Status
      2  Pass
      6  Pass
    #sh wism module 2 controller 1 st
    WiSM Controller 1 in Slot 2 configured with auto-lag
    Operational Status of the Controller : Oper-Up
    Service VLAN                         : 50
    Service Port                         : 3
    Service Port Mac Address             : 6c20.562c.2c61
    Service IP Address                   : 192.168.2.51
    Management IP Address                : 40.96.0.2
    Software Version                     : 7.0.116.0
    Port Channel Number                  : 403
    Allowed-vlan list                    : 1
    Native VLAN ID                       : 1
    WCP Keep Alive Missed                : 0
    #do sh wism st
    Service Vlan : 50, Service IP Subnet : 192.168.2.1/255.255.254.0
          WLAN
    Slot  Controller  Service IP       Management IP    SW Version    Controller Type    Status
    ----+-----------+----------------+----------------+------------+------------------+---------------
    2     1           192.168.2.51     40.96.0.2        7.0.116.0    WS-SVC-WISM-2-K9   Oper-Up
    HQR1#sh ip int brief
    Interface              IP-Address      OK? Method Status                Protocol
    TenGigabitEthernet2/1  unassigned      YES unset  up                    up
    TenGigabitEthernet2/2  unassigned      YES unset  down                  down
    GigabitEthernet2/3     unassigned      YES unset  up                    up
    GigabitEthernet2/4     unassigned      YES unset  administratively down down
    GigabitEthernet6/1     unassigned      YES unset  up                    up
    GigabitEthernet6/2     unassigned      YES unset  down                  down
    GigabitEthernet6/3     unassigned      YES unset  down                  down
    TenGigabitEthernet6/4  unassigned      YES NVRAM  administratively down down
    TenGigabitEthernet6/5  unassigned      YES NVRAM  administratively down down
    Port-channel403        unassigned      YES unset  up                    up
    Vlan1                  40.96.0.1       YES NVRAM  up                    up
    Vlan50                 192.168.2.1     YES NVRAM  up                    up

    Well I feel stupid, apparrently, either by default or by my commands "Web mode" and Secure Web Mode" was disabled.  after enabling, it works.

  • Unable to access Oracle XE Apex Interface

    Hello,
    I've recently installed Oracle XE on Ubuntu (package oracle-xe-universal_10.2.0.1-1.1_i386.deb), however I am unable to access the web interface for Apex. If I use Firefox or Opera, it cannot recognize the file it's trying to access, but reports it as an application/octet-stream file and asks me how to open it or to save it to disk. If I use IE7, it simply displays a few unknown characters (boxes).
    I had the entirety of Oracle XE installed and working prior to rebuilding the server, which is when this problem began happening, but I shouldn't have changed anything to cause a problem like this.
    If anyone can shed some light on this, I would greatly appreciate it, since I've been unsuccessful at finding anything out about this problem.
    Thanks,
    Jeff

    This is a bit old but I've faced the issue and found a (temporary?) solution.
    The problem is caused by a syntax error of the generated HTML on the Change Password page. The APEX page generation code somehow truncated a closing '>' in a tag. By adding a few space, this page generated correctly. However, it seems very likely that the problem will also occur for other pages.
    In file builder/f4350.sql, line 5668, change
      p_plug_source=> s,
    to
      p_plug_source=> s || '  ',
    Then reload the page... I used 'sys as sysdba' and not sure this is the best option. Anyway the page showed afterwards.
    Message was edited by: thtsang

  • Problems access to a web application (Web Interface or Web report)

    Hi,
    We found problems with the access to web application. Some users have problems with direct links to the web applications(Web Interface or Web reporting), when they click on the link an error message appears, the message displays the following text:
    "Cannot open file Bex?sap-language=ENbsplanguge=ENcmd=idoc_TE.."
    Clicking in details the message is "No Access to specified file"
    For this users the access to excel reporting is correct, the message appears when they click on the direct web links through the browser or directly in BW system, but if they type the URL they can access. Other users can use the direct web link without problems.
    I highly appreciate any help or idea about how to solve this issue.
    Thanks in advance.

    HI,
    please ask to your basis that check the language of every single user on su01 tx.
    This is the problem i think.
    Natalia.

  • Unable to Access Web Site (with same name) outside of Local Network

    Hi everyone,
    I have my web site (and some other services) hosted outside of my network by my hosting provider, but handle all other items using OS X Server on my network (i.e. Wiki and so forth).
    The problem is now that I am unable to access my website at www.mydomain.com from within the network. I have external DNS set up for www.mydomain.com to point to my website, while mydomain.com points to my OS X Server (static IP address). Internally in OS X Server's DNS settings this used to work when I had www.mydomain.com resolving to the IP address of my web host, in addition to the default domain settings that OS X had set up. For some reason this is no longer working, and I am unable to figure out why.
    Using latest version of OS X Server 3.0.2.
    Any help is greatly appreciated. Thanks!
    Update: this ended up being a redirect issue on the web host. I added another subdomain that was hosted externally, and it worked fine. For some reason my web host is redirecting www.mydomain.com to domain.com.

    I am in Texas and cannot get to that site either. Do you know for sure the site is up and working? It could just be down (for days, a site I support was down for almost 4 full days a few weeks ago due to a virus problem).
    This may (again, may) be your problem: I see you have a173.48.x.x (you really should x-out the last two octets of your IP address for privacy reasons), I am on a 173.74.x.x address; I know some people have had problems with getting to some sites now that they have a 173.x.x.x address. I think Verizon obtained addresses in that range and some of the addresses apparently previously belonged to spammers or some malicious folks.Some sites (web sites, intermeidate routers, etc.) blocked those addresses, and may not have updated their filters to remove the block on those addresses because they don't know that Verizon now owns them. If this is the problem, eventually those filters will get updated and you will be able to access the site, but this could be a fairly long time.
    If you know how to contact that site I suggest you email them about the problem. You can also try turning off your router overnight and when you turn it back on the next day you may find that you have a different address (one that doesn't start with 173) that will allow you to get to the site.
    I don't think there is much Verizon can do to help, it is not their site that is blocking your address (at least I don't think it is).
    Hope this helps.
    Justin
    Verizon FiOS TV, Internet, and phone
    IMG 1.6.2, Build 08.58
    Keller, TX 76248

Maybe you are looking for

  • How can I sync contacts to IMac, Icloud and Iphone

    My Contacts on my Imac have only one option in settings to sync with my google contacts.  Before Icloud all my contacts and calendar synced just fine between my Imac and Iphone.  Now with Icloud I never seem to be able to sync contact to or from my I

  • How can i stop internet media from flooding elements 6?

    how can I stop elements 6 from constantly importing internet photos and flooding my memory?

  • Internal table modifications

    hello gurus, I got output of a report as bellow. sl no       date                name           state         contry 1            10.10.2009                         mtm 1             10.10.2009     A1                    1            10.10.2009       

  • Cannot send color video. ColorEnable check box is ...

    Hi, I Cannot send color video. ColorEnable check box is disabled. I know the camera allows color but Skype does not allow me to set it up. Any ideas? Thanks in advance!

  • [ERROR] - Runtime Shared Library Preloading Warning

    Hey there guys, I have a question that probably has a very easy answer,  but after searching online for a while I couldn't figure out just how to  fix it. Anyways the problem is this,  when I run it, it gives me this warning and then the when i click