Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Content Management (Extended ECM)
API, SDK, REST and Web Services
LLBadServerCertificateException by using LiveLink Secure Connect Version 9.1.0
T-Systems_Administrator
HiWe try to connect to LiveLink Server with the following code config = (new LLValue()).setAssocNotSet(); config.add("LivelinkCGI",new LLValue( "/livelink_en/livelink" )); config.add("VerifyServer",LLValue.LL_TRUE); config.add("HTTPUserName",new LLValue(username)); config.add("HTTPPassword",new LLValue(pw)); config.add("HTTPS",LLValue.LL_TRUE); LLValue rootCACertsList =new LLValue(); LLSession.GetCARootCerts("/opt/livelink/certs",rootCACertsList); config.add("CARootCerts",rootCACertsList); session =new LLSession(host,port,dbank,username,pw,config);... documents = new LAPI_DOCUMENTS(session); documents.AccessEnterpriseWS((new LLValue()).setAssocNotSet());and have got the following exception, although we have installed the Secure Connect just as described inthe documentation.com.opentext.api.LLBadServerCertificateException: Could not load Certificate Authority Certificates. Unsupported encodingCall Stack:java.security.cert.CertificateException: Unsupported encoding at java.lang.Throwable.fillInStackTrace(Native Method) at java.lang.Throwable.fillInStackTrace(Compiled Code) at java.lang.Throwable.(Compiled Code) at java.lang.Exception.(Exception.java:42) at java.security.GeneralSecurityException.(GeneralSecurityException.java:48) at java.security.cert.CertificateException.(CertificateException.java:44) at sun.security.provider.X509Factory.engineGenerateCertificate(X509Factory.java:96) at java.security.cert.CertificateFactory.generateCertificate(CertificateFactory.java:290) at com.opentext.api.LLSSL.initialize(Compiled Code) at com.opentext.api.LLConnect.executeHTTP(Compiled Code) at com.opentext.api.LLConnect.execute(LLConnect.java:348) at com.opentext.api.LAPI_DOCUMENTS.AccessEnterpriseWS(LAPI_DOCUMENTS.java:40) at test.LLTest.main(LLTest.java:85)Can anyone explain it and give us a hint?Best regards,Huu An
Find more posts tagged with
Comments
Steve_Piatt_(spiatt_(Delete)_891610)
Are the certs in the correct format with all of the header and footer intact?Below is an example of what a typical certificate looks like in the supported format (Base64 encoded sometimes referred to as PEM encoded).-----BEGIN CERTIFICATE-----MIIEqzCCBBSgAwIBAgIKYQ8eHgAAAAAABTANBgkqhkiG9w0BAQUFADCBljEiMCAGCSqGSIb3DQEJARYTc3BpYXR0QG9wZW50ZXh0LmNvbTELMAkGA1UEBhMCVVMxDTALBgNVBAgTBE9oaW8xDzANBgNVBAcTBkR1YmxpbjESMBAGA1UEChMJT3BlbiBUZXh0MRwwGgYDVQQLExNQcm9kdWN0IERldmVsb3BtZW50MREwDwYDVQQDEwhkaWxiZXJ0MjAeFw0wMjA5MTAxMzUwNTVaFw0wMzA5MTAxNDAwNTVaMHsxCzAJBgNVBAYTAlVTMQ0wCwYDVQQIEwRPaGlvMQ8wDQYDVQQHEwZEdWJsaW4xEjAQBgNVBAoTCU9wZW4gVGV4dDEUMBIGA1UECxMLRGV2ZWxvcG1lbnQxIjAgBgNVBAMTGWRpbGJlcnQyLmNvbC5vcGVudGV4dC5jb20wgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAKomSXm/b/cLBMYrTjcWNR7Z/1HTNe+m6Z7mVOkN6jtK5y6pAjMopPzDOHZzpQ6AqeGIfB6s8HCt6RtGvH3sWA6JHLn9yBPZ+MEZPujl8Ly8piyKQkOWsYcfxmHUgY5NYXQAtSMBSXw+ES02oR79Lwb8CdV/k2nYGva2dy15ro7/AgMBAAGjggIYMIICFDAOBgNVHQ8BAf8EBAMCBPAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwHQYDVR0OBBYEFP8DgNKWWazKFlTpARdodvz8dc1nMIHSBgNVHSMEgcowgceAFLdCFFdpHXlblfsDwi1get/i2WvPoYGcpIGZMIGWMSIwIAYJKoZIhvcNAQkBFhNzcGlhdHRAb3BlbnRleHQuY29tMQswCQYDVQQGEwJVUzENMAsGA1UECBMET2hpbzEPMA0GA1UEBxMGRHVibGluMRIwEAYDVQQKEwlPcGVuIFRleHQxHDAaBgNVBAsTE1Byb2R1Y3QgRGV2ZWxvcG1lbnQxETAPBgNVBAMTCGRpbGJlcnQyghBrzD1FJ02JhUlwLnU1gY4WMGkGA1UdHwRiMGAwLaAroCmGJ2h0dHA6Ly9kaWxiZXJ0Mi9DZXJ0RW5yb2xsL2RpbGJlcnQyLmNybDAvoC2gK4YpZmlsZTovL1xcZGlsYmVydDJcQ2VydEVucm9sbFxkaWxiZXJ0Mi5jcmwwgY0GCCsGAQUFBwEBBIGAMH4wPAYIKwYBBQUHMAKGMGh0dHA6Ly9kaWxiZXJ0Mi9DZXJ0RW5yb2xsL2RpbGJlcnQyX2RpbGJlcnQyLmNydDA+BggrBgEFBQcwAoYyZmlsZTovL1xcZGlsYmVydDJcQ2VydEVucm9sbFxkaWxiZXJ0Ml9kaWxiZXJ0Mi5jcnQwDQYJKoZIhvcNAQEFBQADgYEAKeocjV555m/GkhQMO8V0yVuHz76gQfqJVE15m0IoyvY8bv51m4NGQabspq1kiiVKOq0JPutWRb9rjvaMUpzH121XFJv/w6DgdiUs5pyStTQxNXwmWJyd0g32lqqEUKE3fckYiopVQ6gUrQUp2W9X58UJt8VjhX55UEYfj4OUDA4=-----END CERTIFICATE-----
T-Systems_Administrator
The certs are in the correct format. We have got the certificate from IE5 just as described in the documentation.How many certs should be there?
Steve_Piatt_(spiatt_(Delete)_891610)
You only need one certificate. The certificate needed is the one representing the Certificate Authority (CA) that issued the certificate for the server. You do not need to include the ones that are included with LSC.There was a bug with the Java usage of LSC that required that you insure there is no extraneous CR/LF at the end. In other words, if there are any blank lines after the end delimeter, remove it and rerun. This was Bug #1792688.Also, if you are including the certificates from LSC, the one below was the one causing the problem in the bug described. SecureServer.cer If these suggestions do not correct your problem, please submit your issue through Customer Support.Thank you.
T-Systems_Administrator
Thank Steve Piatt very much for the hint.I have tried it again with only one certificate and become the following exception :com.opentext.api.LLSecurityProviderException: Class: fkCould not create socket output stream. Certificate unknownCall Stack:fk: Certificate unknown at gy.a([DashoPro-V1.32-013000]) at dc.e([DashoPro-V1.32-013000]) at dc.getOutputStream([DashoPro-V1.32-013000]) at com.opentext.api.LLConnect.createSocketStreams(LLConnect.java:428) at com.opentext.api.LLConnect.executeHTTP(LLConnect.java:1404) at com.opentext.api.LLConnect.execute(LLConnect.java:348) at com.opentext.api.LAPI_DOCUMENTS.AccessEnterpriseWS(LAPI_DOCUMENTS.java:40) at test.LLTest.main(LLTest.java:85) at com.opentext.api.LLConnect.createSocketStreams(LLConnect.java:451) at com.opentext.api.LLConnect.executeHTTP(LLConnect.java:1404) at com.opentext.api.LLConnect.execute(LLConnect.java:348) at com.opentext.api.LAPI_DOCUMENTS.AccessEnterpriseWS(LAPI_DOCUMENTS.java:40) at test.LLTest.main(LLTest.java:85) Exception com.opentext.api.LLSecurityProviderException: Class: fkCould not create socket output stream. Certificate unknownCall Stack:fk: Certificate unknown at gy.a([DashoPro-V1.32-013000]) at dc.e([DashoPro-V1.32-013000]) at dc.getOutputStream([DashoPro-V1.32-013000]) at com.opentext.api.LLConnect.createSocketStreams(LLConnect.java:428) at com.opentext.api.LLConnect.executeHTTP(LLConnect.java:1404) at com.opentext.api.LLConnect.execute(LLConnect.java:348) at com.opentext.api.LAPI_DOCUMENTS.AccessEnterpriseWS(LAPI_DOCUMENTS.java:40) at test.LLTest.main(LLTest.java:85)My question is that, whether we should use a certificate from a CA. Can we use a self-cerated certificate in the developing phase?Best regards,
Steve_Piatt_(spiatt_(Delete)_891610)
Generally you only need one Cert--the root Certificate Authority (CA) certificate. We have had a couple of customers with hardware SSL accelerators that did not pass back the full certificate chain--especially when the chain is greater than two nodes--that is, when the chain includes intermediate CAs. Generally, this is a setup issue since these hardware devices were not loaded with all of the certificates in the chain. If you were to try loading a server cert without including all of the certs in the chain onto some Web servers, you will not be able to establish an SSL connection because many web servers verify the loaded certificates. Without all of the points in the chain, the verification fails.So from this, if your certs are issued by an intermediate CA, then try exporting all of the certificates in the chain above the server cert and make these available to your LAPI program.