Menu

Connection to OCS server with untrusted SSL cert

Help
2014-11-26
2014-12-03
  • Jesper Jørgensen

    Hi,

    Having problems connecting to a OCS (2007) server with latest Pidgin client (in Ubuntu 14.10 - Pidgin version 2.10.10), SIPE plugin version 1.18.2.

    Error message when connecting is:

    "Unable to validate certificate

    The certificate for <fqdn> could not be validated. The certificate chain presented is invalid."</fqdn>

    I have tried fetching the relevant certificates, and installing them in my home dir (eg. /home/<username>/.purple/certificates/x509/ and under /home/<username>/.purple/certificates/x509/tls_pers</username></username>

    But it still doesnt work - "Authentication failed". It seems that the certificate check has changed from 14.04 to 14.10.

    How can I resolve this error?

     
    • Stefan Becker

      Stefan Becker - 2014-11-27

      I don't think downloading the cert will help you. Pidgin will only allow you accept it temporarily, i.e. you have to accept the request every time. You'll need to find the CA cert, with which signed that cert, and install that one.

      Please be sure to attach the --debug log, because once you have accepted the certificate, the SSL connections should go through. I.e. the "Authentication failed" must have a different cause.

       
  • Jesper Jørgensen

    Hi Stefan,

    thanks for the swift response! Here is the debug log. I tried throwing in the CA cert - cant see that it helped me. As far as I can see, the error lies within "Peer cert did NOT match caced" -and "SEC_ERROR_UNKNOWN_ISSUER". Not sure how to resolve that though.

     

Log in to post a comment.

MongoDB Logo MongoDB