cancel
Showing results for 
Search instead for 
Did you mean: 
sthe
Level 9

User Interface Certificate Error - only in 7.3.1

Hello

Importing or generating a new User Interface Certificate results in the following error when changes are saved:

mwg_cert_error_7.3.1.0.png

The problem appears only in 7.3.1. Tested with JRE 7u17 and 7u9 on Windows 7 x86 and JRE 6u43 on Windows XP.

MWG Version 7.2.0.7 and 7.3.0.2 are not affected.

Beste Regards

Stefan

0 Kudos
15 Replies
asabban
Level 17

Re: User Interface Certificate Error - only in 7.3.1

Hello,

there is a known bug that causes the problem. It will be fixed in a future version.

Best,

Andre

0 Kudos
sthe
Level 9

Re: User Interface Certificate Error - only in 7.3.1

Hello Andre

Thank you for your reply. Would it not be good to publish this issue in KB77166 "Web Gateway 7.3.1 Known Issues"?

Do you know when a fix will be available?

Best

Stefan

Nachricht geändert durch sthe
Added question about the availability of a fix. on 07.03.13 06:11:34 CST
0 Kudos
asabban
Level 17

Re: User Interface Certificate Error - only in 7.3.1

Hello,

I personally would say you are right but I believe the "known issues" list presents the issues that we knew about when the version was published, but it is not a "living" document that is updated whenever a new issue is found. I will check if we can update the document somehow, but I can't promise.

The issue should be fixed in builds larger than 14670, so it should be the next version that comes for or replaces 7.3.1. Unfortunately I am not aware of any timescales yet. If you are interested I can provide you with a workaround that should solve the problem for now, unfortunately it requires some tweaking on the command line and with the configuration files.

Let me know if you are interested.

Best,

Andre

0 Kudos
sthe
Level 9

Re: User Interface Certificate Error - only in 7.3.1

Hello Andre

In KB77166 there is the following sentence: This article will be updated if new issues are identified post-release or if additional information becomes available.”

English is not my native language so do I misunderstand that this should be a living document?

Anyway this is not so important. I think it would be good to have a document with all known bugs at a time. Maybe this would reduce support requests.

Thank you very much for your support. An immediate fix is not necessary as 7.3.1 is only running in a test environment. I just thought it would be good to report this bug.

I really appreciate the fast response and the offer of a workournd. This is very good support!

Best

Stefan

0 Kudos
asabban
Level 17

Re: User Interface Certificate Error - only in 7.3.1

Hi Stefan,

I believe you are right. I should have read the KB article in more detail :-) I will try to talk to one or two people to see what they think. I actually cannot modify the document myself, but I try to find someone who can.

If you are running in a test environment I would leave the shipped certificate in place. Once you get an updated version you will be able to create a new certificate or import your own certificate and all should be fine. If you find out that you want the work around at a later time simply let me know.

Best,

Andre

sthe
Level 9

Re: User Interface Certificate Error - only in 7.3.1

Hi Andre

Thank you for your efforts. It would be nice to know what happens to the KB article. Can you keep me informed please?

I think we will wait until the next official release. The UI is anyway only accessed by a limited number of System Administrators.

And again I am impressed about the good support. Nowadays this is not anymore something taken for granted.

Best

Stefan

0 Kudos
DBO
Level 9

Re: User Interface Certificate Error - only in 7.3.1

I am «finally» building our first WW7 unit in the lab to replace our aging 6.9.1 proxy.  Since it is build on 7.3.1, what is the workaround?

Thank you

0 Kudos
sthe
Level 9

Re: User Interface Certificate Error - only in 7.3.1

Hi

My proposal that you do not have to edit configuration files manually:

  1. Install 7.3.0.2
  2. Import or generate your own certificate
  3. Update the appliance to 7.3.1

Maybe you find this article helpful to create and import your own certificate from a Microsoft CA: KB75037

It describes the process to create and import a custom SubCA certificate but the process is the same for the UI cert.

Best

Stefan

Nachricht geändert durch sthe
spelling corrections on 07.03.13 09:15:42 CST
0 Kudos
asabban
Level 17

Re: User Interface Certificate Error - only in 7.3.1

Hello,

to work around the problem please perform the following steps. Please node that we will modify the MWG configuration on the command line - you should only do this if you feel a little familiar with the instructions. Mistakes can have a bad impact. Also I recommend to do this on non-production systems only (and take a backup :-)).

So:

1.) Connect to MWG via SSH

2.) Change to the folder which contains the file we need to modify

cd /opt/mwg/share/handshake/engines/

3.) Open the file we need to modify in the editor:

vi user_interface.xml

4.) Find the line which needs to be changed. Once in the editor type "/" followed by:

ui.sslcert.key

5.) You will end up in a line that looks like this:

<key variable="ui.sslcert.key" confidential="true" minimum-public-key-length="1024">

6.) Type the "end" button on the keyboard or use cursor keys to jump to the last character of the line.

7.) Move the cursor in front of the closing ">", type "i" for insert

8.) Add

encoding="base64"

9.) You should have a line that looks like this now:

<key variable="ui.sslcert.key" confidential="true" minimum-public-key-length="1024" encoding="base64">

10.) Hit the "Esc" key to leave the insert mode

11.) Type

:wq

to save the file and exist the editor

12.) Restart MWG

service mwg restart

13.) Go to the UI, generate a new certificate again

14.) It should be good now :-)

Best,

Andre

0 Kudos