Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
Encryption activation via key_file failed!
PaulD
ODA: AIX5.2 OD: Version 5.6.0.1.0 Build 41496 Interwoven 20041006
ODB: Win2000 OD: Version 5.6.0.1.0 Build 41496 Interwoven 20041006
I've executed the instructions to create SSL certs on our ODB machine and configured the ODB odbase.xml to use certs -- Works great.
Then I sent them to ODA and configured a deployment on ODA that sends files to ODB using these certs. Works great.
However if I create a reverse deployment on ODA (to grab files from ODB) using the same certs from above, I get this error:
"Encryption activation via key_file failed!"
Why would a regular deployment work and a reverse deployment fail?
(BTW, both the direct deployment and the reverse deployment work without SSL)
thanks in advance
Paul
"confused: please type slowly ..."
Find more posts tagged with
Comments
Adam Stoller
did you set the certificate stuff in the odbase.xml on ODA (I'm assuming that both ODA and ODB are BaseServers - yes?) - and did you restart the BaseServer process on ODA after having done that?
--fish
Senior Consultant, Quotient Inc.
http://www.quotient-inc.com
PaulD
Interesting point. I'm not sure I "can" do that. Let me give you some more information:
we have a 3rd OD server, all it ODAA This thrid server deploys content to the ODA server. I executed the SSL instructions on the ODA server to create the 3 pem files and am using those 3 pem files in odbase.xml to run deployments (forward and reverse) between ODAA and ODA.
Here is a "visual" of what we are trying to do:
ODAA ---> ODA ---> ODB
1) ODAA runs both forward and reverse deployments to ODA
2) ODA runs both forward and reverse deployments to ODB
maybe I've confugred ssl "backwards"?
ODA: AIX5.2 OD: Version 5.6.0.1.0 Build 41496 Interwoven 20041006
ODB: Win2000 OD: Version 5.6.0.1.0 Build 41496 Interwoven 20041006
ODAA: Version 5.6.0.1.0 Build 26834 Interwoven 20031027
Adam Stoller
ODAA and ODA appear to be clearly Base Servers.
ODB from your earlier post sounded like it was a Base Server too (is it? or is it a Receiver?)
Which is the correct "visual"?
ODAA <-[SSL]-> ODA <-[SSL]-> ODB
or
ODAA <-> ODA <-[SSL]-> ODB
In the first case - I believe you need the SSL configured in the server configuration file (odbase.xml and odrcvr.xml [ODB?]) on all three servers. If it's the second case - you might have to check with Support - because I think you may have problems where ODA is expecting non-SSL deployments from ODAA and SSL [reverse] deployments from ODB.
If you [can?] upgrade to OD 6.0.2 I believe you might be able to define "instances" of the server on ODA such that one "instance" is configured for SSL and the other "instance" is not -- but I haven't dealt with this feature of OD so I'm not sure about details there.
--fish
Senior Consultant, Quotient Inc.
http://www.quotient-inc.com
PaulD
Ok, yea, I didnt answer that question:
1) all three servers are Base Servers, and
2) the first visual is the correct one:
ODAA <-[SSL]-> ODA <-[SSL]-> ODB
So your statement "I believe you need the SSL configured in the server configuration file (odbase.xml and odrcvr.xml [ODB?]) on all three servers.", makes perfect sense to me.
However, the part I'm unclear on, then, is this:
On which server do I generate the cacert.pem, newcert.pem, and newreq.pem? Do I generate them on ODAA and then transfer them to ODA and ODB? I'm sooo confused about this ...
thanks, Paul
"confused: please type slowly ..."
Adam Stoller
However, the part I'm unclear on, then, is this:
On which server do I generate the cacert.pem, newcert.pem, and newreq.pem? Do I generate them on ODAA and then transfer them to ODA and ODB? I'm sooo confused about this ...
Hmm - not sure - I haven't done much with SSL deployments in a while - and when I did it was a simple 2-server scenario as opposed to the 3-server scenarios you're involved with.
You could try generating them on ODAA and then copy them to ODA and ODB as needed - but perhaps someone else "here" may be able to provide some information (you should probably open a support case anyway - to try to get the information tracked down internally - just in case the OD engineers aren't getting to DevNet in a timely fashion right now)
--fish
Senior Consultant, Quotient Inc.
http://www.quotient-inc.com
PaulD
Thanks a ton fo talking this out with me. You helped me rule out a few things... eventually I found that if I added IP addresses odnodes.xml and odbase.xml the reverse deploy with SSL worked. whew!
Now, of course, I have the same issue but with a twist. I'm trying to get a reverse encrypted connection working on another pair of OD base servers but this time there is a firewall between them. And I am getting the same "Encryption activation via key_file failed!" on the server the deployment was initiated from and a "Begin out of phase" error on the other one. I guess I'll keep twiddling with the IP/hostnames to see what I can come up with. I know I need to put the firewall in there somewhere ...
thanks again
Paul
"confused . . . please type slowly"