Problems when accessing SGD 4.20.909 with root+intermediate certificates

Hi everybody.

A customer of ours is using SSGD 4.20.909 on a RedHat box with the Security Pack and Firewall Forwarding/Traversal installed and configured.

When he requested his CSR to be signed, a local CA (which is a branch of Verisign) signed it with a CA which is an intermediate one; as a result Classic Webtop connections worked fine but he had to put the ca.pem file (which contains BOTH the root and intermediate certificates used to sign his CSR) into the Native Client installation folder as to get in recognized by the Native Client itself.

Now the last problem is with the Browser Based Webtop: in fact, if you try by accessing the https://<server>/sgd, after a while you get the:

Secure Global Desktop connection lost

The connection to Secure Global Desktop server has been lost. The error reported was:

Unable to connect: Connection refused

To reconnect, we suggest you restart your web browser and try logging into Secure Global Desktop again.

If problems persist, contact a Secure Global Desktop Administrator.

The strange thing is that if I try accessing the very same server but with the classic webtop from my desktop (https://server/tarantella), everything works as expected and the same goes for the Native Client.

I have to tell that I'm using a Linux box which is behind a firewall/proxy and in the above cases I'm prompted for the proxy credentials whereas I'm not for the Browser Based Webtop.

I've also tried from a different box (Windows XP) and I have the very same results.

The strange thing is that I tried last Friday and Monday and I was able to get to the login prompt using the BBW but I'm not able to do it any longer; the customer reported he didn't change anything on the server.

I do know that he made the modifications reported here

https://<server>/tarantella/help/en-us/tsp/gettingstarted/secure_webservi ces.html

as to secure SOAP connections but I'm not sure about what he did.

Given both the classic webtop and the native client do work fine, is there anything a can check as to find the reason of this issue?

The thing which puzzles me is that I'm not prompted for my proxy username & password so perhaps something is wrong on the Tomcat side?

Thanks,

Rob

[2352 byte] By [Rob_Z] at [2007-11-25 22:17:48]
# 1
Hi,might be a guess to check the SOP connection - are the right certificates installed / is the connection modified at all?
bongout at 2007-7-5 2:10:53 > top of Java-index,Desktop,Sun Secure Global Desktop Software...