1 2 Previous Next 15 Replies Latest reply: Mar 7, 2013 10:37 AM by asabban RSS

    User Interface Certificate Error - only in 7.3.1

    sthe

      Hello

       

      Importing or generating a new User Interface Certificate results in the following error when changes are saved:

      mwg_cert_error_7.3.1.0.png

      The problem appears only in 7.3.1. Tested with JRE 7u17 and 7u9 on Windows 7 x86 and JRE 6u43 on Windows XP.

      MWG Version 7.2.0.7 and 7.3.0.2 are not affected.

       

      Beste Regards

       

      Stefan

        • 1. Re: User Interface Certificate Error - only in 7.3.1
          asabban

          Hello,

           

          there is a known bug that causes the problem. It will be fixed in a future version.

           

          Best,

          Andre

          • 2. Re: User Interface Certificate Error - only in 7.3.1
            sthe

            Hello Andre

             

            Thank you for your reply. Would it not be good to publish this issue in KB77166 "Web Gateway 7.3.1 Known Issues"?

            Do you know when a fix will be available?

             

            Best

            Stefan

             

            Nachricht geändert durch sthe Added question about the availability of a fix. on 07.03.13 06:11:34 CST
            • 3. Re: User Interface Certificate Error - only in 7.3.1
              asabban

              Hello,

               

              I personally would say you are right but I believe the "known issues" list presents the issues that we knew about when the version was published, but it is not a "living" document that is updated whenever a new issue is found. I will check if we can update the document somehow, but I can't promise.

               

              The issue should be fixed in builds larger than 14670, so it should be the next version that comes for or replaces 7.3.1. Unfortunately I am not aware of any timescales yet. If you are interested I can provide you with a workaround that should solve the problem for now, unfortunately it requires some tweaking on the command line and with the configuration files.

               

              Let me know if you are interested.

               

              Best,

              Andre

              • 4. Re: User Interface Certificate Error - only in 7.3.1
                sthe

                Hello Andre

                 

                In KB77166 there is the following sentence: This article will be updated if new issues are identified post-release or if additional information becomes available.”

                English is not my native language so do I misunderstand that this should be a living document?

                Anyway this is not so important. I think it would be good to have a document with all known bugs at a time. Maybe this would reduce support requests.

                 

                Thank you very much for your support. An immediate fix is not necessary as 7.3.1 is only running in a test environment. I just thought it would be good to report this bug.

                 

                I really appreciate the fast response and the offer of a workournd. This is very good support!

                 

                Best

                Stefan

                • 5. Re: User Interface Certificate Error - only in 7.3.1
                  asabban

                  Hi Stefan,

                   

                  I believe you are right. I should have read the KB article in more detail :-) I will try to talk to one or two people to see what they think. I actually cannot modify the document myself, but I try to find someone who can.

                   

                  If you are running in a test environment I would leave the shipped certificate in place. Once you get an updated version you will be able to create a new certificate or import your own certificate and all should be fine. If you find out that you want the work around at a later time simply let me know.

                   

                  Best,

                  Andre

                  • 6. Re: User Interface Certificate Error - only in 7.3.1
                    DBO

                    I am «finally» building our first WW7 unit in the lab to replace our aging 6.9.1 proxy.  Since it is build on 7.3.1, what is the workaround?

                     

                    Thank you

                    • 7. Re: User Interface Certificate Error - only in 7.3.1
                      sthe

                      Hi Andre

                       

                      Thank you for your efforts. It would be nice to know what happens to the KB article. Can you keep me informed please?

                       

                      I think we will wait until the next official release. The UI is anyway only accessed by a limited number of System Administrators.

                       

                      And again I am impressed about the good support. Nowadays this is not anymore something taken for granted.

                       

                      Best

                      Stefan

                      • 8. Re: User Interface Certificate Error - only in 7.3.1
                        sthe

                        Hi

                         

                        My proposal that you do not have to edit configuration files manually:

                         

                        1. Install 7.3.0.2
                        2. Import or generate your own certificate
                        3. Update the appliance to 7.3.1

                         

                        Maybe you find this article helpful to create and import your own certificate from a Microsoft CA: KB75037

                        It describes the process to create and import a custom SubCA certificate but the process is the same for the UI cert.

                         

                        Best

                        Stefan

                         

                        Nachricht geändert durch sthe spelling corrections on 07.03.13 09:15:42 CST
                        • 9. Re: User Interface Certificate Error - only in 7.3.1
                          asabban

                          Hello,

                           

                          to work around the problem please perform the following steps. Please node that we will modify the MWG configuration on the command line - you should only do this if you feel a little familiar with the instructions. Mistakes can have a bad impact. Also I recommend to do this on non-production systems only (and take a backup :-)).

                           

                          So:

                           

                          1.) Connect to MWG via SSH

                          2.) Change to the folder which contains the file we need to modify

                           

                          cd /opt/mwg/share/handshake/engines/

                           

                          3.) Open the file we need to modify in the editor:

                           

                          vi user_interface.xml

                           

                          4.) Find the line which needs to be changed. Once in the editor type "/" followed by:

                           

                          ui.sslcert.key

                           

                          5.) You will end up in a line that looks like this:

                           

                          <key variable="ui.sslcert.key" confidential="true" minimum-public-key-length="1024">

                           

                          6.) Type the "end" button on the keyboard or use cursor keys to jump to the last character of the line.

                           

                          7.) Move the cursor in front of the closing ">", type "i" for insert

                           

                          8.) Add

                           

                          encoding="base64"

                           

                          9.) You should have a line that looks like this now:

                           

                          <key variable="ui.sslcert.key" confidential="true" minimum-public-key-length="1024" encoding="base64">

                           

                          10.) Hit the "Esc" key to leave the insert mode

                           

                          11.) Type

                           

                          :wq

                           

                          to save the file and exist the editor

                           

                          12.) Restart MWG

                           

                          service mwg restart

                           

                          13.) Go to the UI, generate a new certificate again

                           

                          14.) It should be good now :-)

                           

                          Best,

                          Andre

                          1 2 Previous Next