Problems when accessing SGD 4.20.909 with root+intermediate certificates
Hi everybody.
A customer of ours is using SSGD 4.20.909 on a RedHat box with the Security Pack and Firewall Forwarding/Traversal installed and configured.
When he requested his CSR to be signed, a local CA (which is a branch of Verisign) signed it with a CA which is an intermediate one; as a result Classic Webtop connections worked fine but he had to put the ca.pem file (which contains BOTH the root and intermediate certificates used to sign his CSR) into the Native Client installation folder as to get in recognized by the Native Client itself.
Now the last problem is with the Browser Based Webtop: in fact, if you try by accessing the https://<server>/sgd, after a while you get the:
Secure Global Desktop connection lost
The connection to Secure Global Desktop server has been lost. The error reported was:
Unable to connect: Connection refused
To reconnect, we suggest you restart your web browser and try logging into Secure Global Desktop again.
If problems persist, contact a Secure Global Desktop Administrator.
The strange thing is that if I try accessing the very same server but with the classic webtop from my desktop (https://server/tarantella), everything works as expected and the same goes for the Native Client.
I have to tell that I'm using a Linux box which is behind a firewall/proxy and in the above cases I'm prompted for the proxy credentials whereas I'm not for the Browser Based Webtop.
I've also tried from a different box (Windows XP) and I have the very same results.
The strange thing is that I tried last Friday and Monday and I was able to get to the login prompt using the BBW but I'm not able to do it any longer; the customer reported he didn't change anything on the server.
I do know that he made the modifications reported here
https://<server>/tarantella/help/en-us/tsp/gettingstarted/secure_webservi ces.html
as to secure SOAP connections but I'm not sure about what he did.
Given both the classic webtop and the native client do work fine, is there anything a can check as to find the reason of this issue?
The thing which puzzles me is that I'm not prompted for my proxy username & password so perhaps something is wrong on the Tomcat side?
Thanks,
Rob

