VCS' certificates for transversal zone / unable to to connect to server TLS negotiation failure

Hi,
I am trying to connect two traversal zones VCSE as a server and VCSC as a client but i am having the next error:
VCSE:
tvcs: Event="Inbound TLS Negotiation Error" Service="SIP" Src-ip="10.1.1.1" Src-port="25234" Dst-ip="10.1.1.10" Dst-port="7001" Detail="tlsv1 alert unknown ca" Protocol="TLS" Level="1" UTCTime="2015-01-28 18:51:09,080"
VCSC:
2015-01-28T14:32:09-04:30tvcs: Event="Outbound TLS Negotiation Error" Service="SIP" Src-ip="192.168.1.2" Src-port="25267" Dst-ip="10.1.1.10" Dst-port="7001" Detail="unable to get local issuer certificate" Protocol="TLS" Common-name="name-vcse.myname.com" Level="1" UTCTime="2015-01-28 19:02:09,081"
I follow the steps in this document: "http://www.cisco.com/c/dam/en/us/td/docs/telepresence/infrastructure/vcs/config_guide/X8-2/Cisco-VCS-Certificate-Creation-and-Use-Deployment-Guide-X8-2.pdf" and trying with Windows Server Authentication and Client Authentication and with OpenSSL but have the same results.
In my firewall i can telnet the 10.1.1.10 port 7001 and also from a device from the network 192.168.1.0 to 10.1.1.10 port 7001 (not firewall issues i think)
Also i tested the certificate in my VCSC and get the following error:
Invalid: The client certificate is not signed by a CA in the trusted CA list. 
Any ideas?
Regards,

Anthony,
You're missing the Certificate Authority certificate who signed one of the servers certs. Presumably what is missing is the CA (root) certificate that signed the Expressway-E's cert. Here is a general rule of thumb.
The certificate of the signer of the VCS-C/Expressway-C certificate should be present on the VCS-E/Expressway-E under the Trusted CA section.
The certificate of the signer of the VCS-E/Expressway-E certificate should be present on the VCS-CExpressway-C under the Trusted CA section.
it's not uncommon that you could be dealing with a condition where one of the servers certs was signed by an intermediate. If this is the case you simply just need to follow the chain of the certificates and make sure they are all included within the Trusted CA list on the respective server. The main thing to look at with the certificates are the Common Names of the Subject and Issuer. Below is an example of a fake certificate.
VCS-E/Expressway-E Cert
Issuer: CN=RootCAIntermediate – G5     <-- Signer
Subject: CN=Expressway-E.domain.com
RootCAIntermediate –G5 Certificate
Issuer: CN=RootCAIntermediate Trust    <-- Signer
Subject: CN=RootCAIntermediate – G5
RootCAIntermediate Trust
Issuer: CN=RootCA   <-- Signer
Subject: CN=RootCAIntermediate Trust
RootCA Certificate
Issuer: CN=RootCA   <-- Signer
Subject: CN=RootCA
If you are missing anyone of these, you will get the unknown CA error. When the RootCA (The real root) is uploaded to the VCS/Expressway server it’s Issuer will be RootCA and the Subject will be “Matches Issuer”.
I hope this can help you.
-P

Similar Messages

  • 1000: unable to make connection to server or to find FLV

    Hi,
    this is driving me crazy. This is so simple, I can't believe
    there is a problem. I placed and FLVPlayback component in my flash
    file, and named it "my_playback".
    I created an actions layer and in it I do:
    my_playback.contentPath("moviename.flv") ;
    and the stupid flash gives me the error when I run it :
    1000:unable to make connection to server or to find FLV.
    Now the damn "moviename.flv" is in he same directory as the
    flash file, so what is going on?
    I just can't believe that the simplest things are are so hard
    with Flash, I am getting so annoyed by it, I am almost ready to
    give up on Flash.
    Does someone have an idea of what is going on?
    thanks
    -Malena

    no idea..
    what version of flash?
    what is in the contentPath parameter for that component
    instance?
    I cant reproduce your problem, can I have your fla
    file?

  • I can't update my ipod. When I check for updates it says "can't connect to server"(despite internet connection being fine). Also, when I try and update software it starts then stops after 2 seconds

    I can't update my Ipod. When I check for updates it says "can't connect to server" despite internet connection being fine. When I receive a software update message;I say install and it starts updating then stops after 2 seconds. Help! (It is a 3rd gen IPod touch(I think)). Presumably as a result of this, I have tried to put my library onto my gf's new iPod touch and it just charges it..doesn't download my library onto the touch).

    Update Server
    Try:
    - Powering off and then back on your router.
    - iTunes for Windows: iTunes cannot contact the iPhone, iPad, or iPod software update server
    - Change the DNS to either Google's or Open DNS servers
    Public DNS — Google Developers
    OpenDNS IP Addresses
    - For one user uninstalling/reinstalling iTunes resolved the problem
    - Try on another computer/network
    - Wait if it is an Apple problem

  • VideoError: 1000: Unable to make connection to server or to find FLV on server

    Hello there,
    I am using a simple FLVPlayback control in my AS3 document. In that I invoked FLVPlayback's methods like play, seek, and stop. Whenever I use these methods I get "VideoError: 1000: Unable to make connection to server or to find FLV on server" error while publishing the file. If I remove these method call then I am not getting this error.
    Note: If I load above published file in another file then I'm not getting this error, however same is not working on LMS.
    It will be of great help if someone help me resolve this issue.

    I added trace that you have mentioned in first frame and here is output:
    Player Name :: vPlayer
    Player Source :: courseContent/LN_1324634806568/sampleVideo_01.mp4
    VideoError: 1000: Unable to make connection to server or to find FLV on server
              at fl.video::VideoPlayer/stop()
              at fl.video::FLVPlayback/http://www.adobe.com/2007/flash/flvplayback/internal::showFirstStream()
              at fl.video::FLVPlayback/http://www.adobe.com/2007/flash/flvplayback/internal::handleVideoEvent()
              at flash.events::EventDispatcher/dispatchEventFunction()
              at flash.events::EventDispatcher/dispatchEvent()
              at fl.video::VideoPlayer/http://www.adobe.com/2007/flash/flvplayback/internal::setState()
              at fl.video::VideoPlayer/http://www.adobe.com/2007/flash/flvplayback/internal::httpNetStatus()

  • VideoError: 1000: Unable to make connection to server

    VideoError: 1000: Unable to make connection to server or to
    find FLV on server
    I've spent a lot of time in the past couple of weeks trying
    to figure out what could be the problem.
    I developed a Live Streaming Flash (swf) that play fine in my
    local host with my Labtop with FMS3 Installed.I can see my live
    video in internet only when i use my laptop. What puzzled me is
    that even when i connected to Internet my Live stream and the
    dynamic playlist work perfect on my laptop but never in any other
    computer. I have tested it on several computers in different
    places, the only thing i get always is this code;
    VideoError: 1000: Unable to make connection to server or to
    find FLV on server
    at fl.video::VideoPlayer/play()
    at fl.video::FLVPlayback/
    http://www.adobe.com/2007/flash/flvplayback/internal::showFirstStream()
    at fl.video::FLVPlayback/
    http://www.adobe.com/2007/flash/flvplayback/internal::handleVideoEvent()
    at
    flash.events::EventDispatcher/flash.events:EventDispatcher::dispatchEventFunctio
    n()
    at flash.events::EventDispatcher/dispatchEvent()
    at fl.video::VideoPlayer/
    http://www.adobe.com/2007/flash/flvplayback/internal::setState()
    at fl.video::VideoPlayer/
    http://www.adobe.com/2007/flash/flvplayback/internal::httpNetStatus()
    Does anybody know what can cause this error and how to fix
    it?
    Thanks in advance,
    Delluchi

    I can't answer your question but it sounds like you have a similar problem to me, I can make the connection fine from my laptop but no other pc can connect or see the stream. Why can't someone just tell you in plain english how to ....  better still why can't Adobe actually tell you in plain english! Hope you work it out, if you do let me know please!

  • TS4006 when i put my password in for icloud,it says can't connect to server?

    i am trying to try out the find my iphone app , i went to icloud.com and put my id and password in, and a message came back saying couldn't connect to server?

    Update Server
    Try:
    - Powering off and then back on your router.
    - iTunes for Windows: iTunes cannot contact the iPhone, iPad, or iPod software update server
    - Change the DNS to either Google's or Open DNS servers
    Public DNS — Google Developers
    OpenDNS IP Addresses
    - For one user uninstalling/reinstalling iTunes resolved the problem
    - Try on another computer/network
    - Wait if it is an Apple problem

  • Firefox browser wont open the message I get is "unable to establish connection to server" even though I am online

    I was in the middle of a firfox browser sessions, but had to close it down as computer was playing up with other pograms I had open. When rebooted the system, I could not use the firefox browser and had the following message:
    '''Firefox can't establish a connection to the server at search.findeer.com.
    '' The site could be temporarily unavailable or too busy. Try again in a few
    moments.
    If you are unable to load any pages, check your computer's network
    connection.
    If your computer or network is protected by a firewall or proxy, make sure
    that Firefox is permitted to access the Web''.'''
    i then uninstalled it restarted my computer reinstalled it restarted my computer and had the same message come up when trying to open it.

    A possible cause is security software (firewall) that blocks or restricts Firefox or the plugin-container process without informing you, possibly after detecting changes (update) to the Firefox program.
    Remove all rules for Firefox from the permissions list in the firewall and let your firewall ask again for permission to get full unrestricted access to internet for Firefox and the plugin-container process and the updater process.
    See:
    *https://support.mozilla.com/kb/Server+not+found
    *https://support.mozilla.com/kb/Firewalls

  • Unable to send - connection to server timed out

    I'm lately having problems sending mail with Mail.app. A few days ago I started getting the following error message:
    Cannot send message using the server smtp.mac.com:username
    The connection to the server "smtp.mac.com" on port 993 timed out.
    I didn't deal with it at the time because I was using a hotel wireless connection and just assumed it was a problem with their setup; however, I'm now having the problem at home.
    I haven't changed any settings at all, and it started before installing the latest update. Does anyone have an idea what might be causing this and what to do about it?
    Thanks, Rick

    When I first set up this account, under the advanced tab it had port 993 by default, but it was grayed out. I was unable to change it using mail.app preferences, but tried a test message, and when it wouldn't send used the option to edit the server list. I changed it to port 25 there, and it now works. For some reason, when I look at the advance tab under preferences, it still has port 993 and still grayed out. It now works, but I don't understand why it would still show port 993.
    In any case, thanks for the help.

  • IOS6 Update for my ipad3 but can't connect to server?

    IOS6 installed on my ipad3 but get getting "Could not sign in" There was a problem connecting to the server when putting in Apple ID login?

    You must not have a wifi internet connection.
    iOS 6 Wifi Problems/Fixes
    Fix For iOS 6 WiFi Problems?
    http://tabletcrunch.com/2012/09/27/fix-ios-6-wifi-problems/
    Did iOS 6 Screw Your Wi-Fi? Here’s How to Fix It
    http://gizmodo.com/5944761/does-ios-6-have-a-wi+fi-bug
    How To Fix Wi-Fi Connectivity Issue After Upgrading To iOS 6
    http://www.iphonehacks.com/2012/09/fix-wi-fi-connectivity-issue-after-upgrading- to-ios-6.html
    iOS 6 iPad 3 wi-fi "connection fix" for netgear router
    http://www.youtube.com/watch?v=XsWS4ha-dn0
    Apple's iOS 6 Wi-Fi problems
    http://www.zdnet.com/apples-ios-6-wi-fi-problems-linger-on-7000004799/
    ~~~~~~~~~~~~~~~~~~~~~~~
    Look at iOS Troubleshooting Wi-Fi networks and connections  http://support.apple.com/kb/TS1398
    iPad: Issues connecting to Wi-Fi networks  http://support.apple.com/kb/ts3304
    iOS: Recommended settings for Wi-Fi routers and access points  http://support.apple.com/kb/HT4199
    Additional things to try.
    Try this first. Turn Off your iPad. Then turn Off (disconnect power cord for 30 seconds or longer) the wireless router & then back On. Now boot your iPad. Hopefully it will see the WiFi.
    Go to Settings>Wi-Fi and turn Off. Then while at Settings>Wi-Fi, turn back On and chose a Network.
    Change the channel on your wireless router (Auto or Channel 6 is best). Instructions at http://macintoshhowto.com/advanced/how-to-get-a-good-range-on-your-wireless-netw ork.html
    Another thing to try - Go into your router security settings and change from WEP to WPA with AES.
    How to Quickly Fix iPad 3 Wi-Fi Reception Problems
    http://osxdaily.com/2012/03/21/fix-new-ipad-3-wi-fi-reception-problems/
    If none of the above suggestions work, look at this link.
    iPad Wi-Fi Problems: Comprehensive List of Fixes
    http://appletoolbox.com/2010/04/ipad-wi-fi-problems-comprehensive-list-of-fixes/
    Fix iPad Wifi Connection and Signal Issues  http://www.youtube.com/watch?v=uwWtIG5jUxE
    Fix Slow WiFi Issue https://discussions.apple.com/thread/2398063?start=60&tstart=0
    Unable to Connect After iOS Update - saw this solution on another post.
    https://discussions.apple.com/thread/4010130
    Note - When troubleshooting wifi connection problems, don't hold your iPad by hand. There have been a few reports that holding the iPad by hand, seems to attenuate the wifi signal.
    ~~~~~~~~~~~~~~~
    If any of the above solutions work, please post back what solved your problem. It will help others with the same problem.
     Cheers, Tom

  • Long time for a Mail Client to verify connection to server normal?

    Server: Tiger (G4)
    Client: Leopard Mail.app (G5 iMac)
    Local network.
    When adding an imap account it takes a long time to verify the inbound and outbound (same server) connection. I don't have actual time but it seems like a long time and is much longer than it takes to get a cup of java.
    Does it do a lot of checking or do I have a mail server problem is what my concern is.
    It (mail app) always carries on, I.e. is happy to use the server eventually.

    H,
    my first guess would be at DNS. Are you using internal DNS? If so is it the first on the list at the client (system prefs---network).
    There are several different schools of thought on this (network geeks can have serious religious disagreements about this, just add beer and we'll argue it for days) but where possible, run internal DNS on the mailserver that, at least, knows about itself and point your clients at it. DNS is virtually no load on the server (even with a LOT of clients hitting it, its pretty lightweight) and can speed up a number of things. Just remember to point the server at itself as its first DNS as well by using 127.0.0.1 and giving it a valid search domain (your domain.com).
    My $.02 Hope it Helps
    Sean

  • TS3899 Is there a reason for Yahoo mail to keep saying connection to server failed

    Is there a reason why my Ipad keeps saying the connection to the server failed using my mail app but
    i can gain entry to my account using Google then Yahoo mail.

    Other than yahoo being a general pain in the behind?
    It's been buggy at best for quite a while now. I have noticed that it doesn't like some connections, for example my mail simply will not download if I'm on certain AT&T hotspots via the mail app, but works just fine if I access it via safari.
    I also had periods of time just this AM when my PC wouldn't even access my mail. IMHO, Yahoo has upgraded their mail to nice pretty barely function.
    If it persists too long you can try to uninstall/reinstall your mail account in the mail app (Under settings, mail, contacts and calendar). Or it may simply be your connection or hotspot and it will resolve once you use a different connection.
    I believe yahoo mail also has an app but I have no experience with how well it may/may not work

  • "unable to open connection to server" error.

    I just started to get this error message when ever my Casio Commando droid tries to open my comcast or hotmail accounts. These accounts have worked perfectly for over a year but stoped on about 4/1. and now this popup error message is displayed.
    How do I correct this problem?
    Thanks

    Well have you tried running a power cycle to refresh the phone that might help to get it back to receiving your emails you might if you haven't tried this)  clearing the system cache partition and if there's been any recent updates to the phone it might be a good thing to update the phone.. Hope this helps b33

  • A pop-up window advising of software update for Firefox appears and does not connect with server

    The window suggests strongly that I update software but when I attempt to update it does nothing but try to connect with server and never does

    * http://kb.mozillazine.org/Software_Update (Software Update not working properly)
    Remove the files in the updates and updates\0 folder.
    You may need to delete active-update.xml and updates.xml as well if present.<br />
    XP:
    C:\Documents and Settings\&lt;user&gt;\Local Settings\Application Data\Mozilla\Firefox\Mozilla Firefox\updates
    (%USERPROFILE%\Local Settings\Application Data\Mozilla\Firefox\Mozilla Firefox)
    If you have problems with updating then best is to download the full version and uninstall the currently installed version.
    You may need to remove the Firefox program folder to do a clean install of the new version.
    Do a clean (re-)install:
    Download a fresh Firefox copy and save the file to the desktop.
    * Firefox 4.0.x: http://www.mozilla.com/en-US/firefox/all.html
    * Uninstall your current Firefox version and remove the Firefox program folder before installing that copy of the Firefox installer.
    * Do not remove personal data if you uninstall the current version.
    * It is important to delete the Firefox program folder to remove all the files and make sure that there are no problems with files that were leftover after uninstalling.
    Your bookmarks and other profile data are stored elsewhere in the [http://kb.mozillazine.org/Profile_folder_-_Firefox Firefox Profile Folder] and won't be affected by a reinstall, but make sure that you do not select to remove personal data if you uninstall Firefox.

  • Default VCS certificate - SIP-TLS Local Database Registration

    Hi,
    Can someone please tell me if it's possible to use the default VCS certificate for SIP-TLS registration for endpoints listed under the local database? If so will this work by default or is there extra configuration required?
    Thanks

    Hello Ovindo -
    Because you're running a VCS with X7.2.2 software, and using an guide that's meant for X7.0, what you're looking for has changed since that guide.
    Please take a look at the X7.2.2 release notes on page 10, "Device Authentication".
    You should be using this device authentication guide for your version of VCS software.

  • Failed to create machine self-signed certificate for site role [SMS_SQL_SERVER]

    SCCM 2012 has been successfully installed on the server:
    SRVSCCM.
    The database is on SQL Server 2008 R2 SP1 CU6 Failover Cluster (CLS-SQL4\MSSQLSERVER04)
    Cluster nodes: SQL01 and SQL01. On all nodes made necessary the Security Setup of SCCM. No errors and warning on SCCM Monitoring.
    The cluster service is running on the account: sqlclusteruser
    The account has the appropriate SPN are registered:
    setspn -L domain\sqlclusteruser
    Registered ServicePrincipalNames for CN=SQL Cluster,OU=SQL,OU=Users special,OU=MAIN,DC=domain,DC=local:
    MSSQLSvc/CLS-SQL4
    MSSQLSvc/CLS-SQL4.domain.local
    MSSQLSvc/CLS-SQL4:11434
    MSSQLSvc/CLS-SQL4.domain.local:11434
    After some time on the cluster hosts every day started appearing new folders with files inside:
    srvboot.exe
    srvboot.ini
    srvboot.log
    srvboot.log contains the following information:
    SMS_SERVER_BOOTSTRAP_SRVSCCM.domain.local_SMS_SQL_SERVER started.
    Microsoft System Center 2012 Configuration Manager v5.00 (Build 7711)
    Copyright (C) 2011 Microsoft Corp.
    Command line: "SMS_SERVER_BOOTSTRAP_SRVSCCM.domain.local_SMS_SQL_SERVER CAS K:\SMS_SRVSCCM.domain.local_SMS_SQL_SERVER8 /importcertificate SOFTWARE\MicrosoftCertBootStrap\ SMS_SQL_SERVER".
    Set current directory to K:\SMS_SRVSCCM.domain.local_SMS_SQL_SERVER8.
    Site server: SRVSCCM.domain.local_SMS_SQL_SERVER.
    Importing machine self-signed certificate for site role [SMS_SQL_SERVER] on Server [SQL01]...
    Failed to retrieve SQL Server service account.
    Bootstrap operation failed: Failed to create machine self-signed certificate for site role [SMS_SQL_SERVER].
    Disconnecting from Site Server.
    SMS_SERVER_BOOTSTRAP_SRVSCCM.domain.local_SMS_SQL_SERVER stopped.

    The site server is trying to install the sms_backup agent on the SQL Server Cluster nodes.
    Without successfull bootstrap the siteserver backup is not able to run successfully.
    Try grant everyone the read permisson on
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SMS on the SQL server nodes.
    This worked for me.
    After that a Folder named "SMS_<SITESERVER-FQDN>" appeared on C: on the SQL Cluster nodes, and a "SMS_SITE_SQL_BACKUP_FQDN" Service should be installed.
    After the new Folder is created and the new Service is installed, you can safely remove the bootstrap Service by opening a command prompt and enter:
    sc delete "SMS_SERVER_BOOTSTRAP_FQDN-of-SiteServer_SMS_SQL_SERVER"

Maybe you are looking for

  • How to retrieve material document no. based on production confirmation no.

    Hi Friends, I am retreiving the production confirmation number(PRTNR) thru bapi BAPI_REPMANCONF_CREATE_MTS. Based on that confirmation number I need to retrieve material document number (MBLNR) Because multiple users can post finished goods from diff

  • How to install Flash Player on Power PC with OS 10.5.8

    I have a Mac with OS 10.5.8. I keep following the instructions and trying to upgrade to the newest version that seems compatible, but keep getting brought back to the original issue - that Power PC are no longer supported. So it's a unending cycle. H

  • CVS not working correctly in Leopard

    I installed xCode Developer Tools. In the past, cvs would work out of the box after installing developer tools, now it doesn't work transparently and there isn't even a manual entry available for cvs. Bbedit CVS integration is broken as a result (or

  • Unable to add discount

    Hi Experts On the incoming payment screen trying to add a discount amount which is under 0.05 and as soon as you enter this it goes away. If you enter 0.05 or above it will remain. whats causeing this Thank you Regards Apsara

  • Missing Parameter - Global Date Variable

    I am trying to use a global variable for a date in my interface. I have the variable declared on the schema of my staging area and when I refresh it it works fine. I put the variable as refresh followed by the interface in a package. When I run the p