Unable to login through SGD Webtop vs. (Ttarantella Webtop & Native Client)

We have a problem on TTA 4.1.903 where we have just recently installed a new Thawte SSL certificate pointing at:

Thawte Server CA

We can successfully login through:

A. A Browser pointing at https://www.mycompany.com/tarantella/

B. Native Client pointing at https://www.mycompany.com/tarantella/

But when we try to login through a browser to:

https://www.mycompany.com/sgd/

We get the following errors on various popups:

This application Digital signature has an error. Do you want to run? (we say yes)

Cannot connect to the server www.mycompany.com:443 Server Certificate has expired

The TTA command "$tta/bin/tarantella security certinfo" validates the certificate as good and so does the browser when you click on the SSL Lock icon.

Interesting factoid, ONE of our staff who logs in with a Win2K box can get in with no problem, but everyone else is using WinXP.

Also everyone has a JRE in excess of 1.4, so the msg in the error file below doesnt apply.

The TTA Error Log file at: $tarantella/var/log/error.log file gives us msgs like:

2006/01/20 15:07:41.137 ssl26146ssldaemon/handshake/failederror

Tarantella Secure Global Desktop Enterprise Edition (4.1) ERROR:

TSP=192.168.50.2:443 Client=192.168.11.241:1862

The client has established a TCP connection but failed to negotiate

an SSL connection. Connection closed by Tarantella Security Daemon.

Reported SSL error: tlsv1 alert unknown ca

Check the client supports SSL.

Web browsers must support JDK 1.1. ssldaemon/handshake/failederror

2006/01/20 15:07:41.137 ssl26146ssldaemon/handshake/failederror

Tarantella Secure Global Desktop Enterprise Edition (4.1) ERROR:

TSP=192.168.50.2:443 Client=192.168.11.241:1862

The client has established a TCP connection but failed to negotiate

an SSL connection. Connection closed by Tarantella Security Daemon.

Reported SSL error: tlsv1 alert unknown ca

Check the client supports SSL.

Web browsers must support JDK 1.1. ssldaemon/handshake/failederror

2006/01/20 15:07:41.137 ssl26146ssldaemon/handshake/incompleteerror

Tarantella Secure Global Desktop Enterprise Edition (4.1) ERROR:

Client 192.168.11.241:1862 has failed to complete an initial SSL connection.

Reported SSL error:

Check the client supports SSL. Web browsers must support JDK 1.1.

Check client for errors. ssldaemon/handshake/incompleteerror

2006/01/20 15:07:41.137 ssl26146ssldaemon/handshake/incompleteerror

Tarantella Secure Global Desktop Enterprise Edition (4.1) ERROR:

Client 192.168.11.241:1862 has failed to complete an initial SSL connection.

Reported SSL error:

Check the client supports SSL. Web browsers must support JDK 1.1.

Check client for errors. ssldaemon/handshake/incompleteerror

[2945 byte] By [aspenhedge] at [2007-11-25 21:38:06]
# 1
try this link. It talks about the problem and I think Im having the same issue http://sunsolve.sun.com/search/document.do?assetkey=1-26-57436-1
courtsh at 2007-7-5 0:28:57 > top of Java-index,Desktop,Sun Secure Global Desktop Software...
# 2
Easier way though is if you delete the expired certs in the clients browser from verisign and thawte. Intermidiates and the roots that have expired
courtsh at 2007-7-5 0:28:57 > top of Java-index,Desktop,Sun Secure Global Desktop Software...