Question

Problem fixing SSL Certificates in NW 6.5

Asked by: 2mrchio

NW 6.5 server, SP8

In an attempt to install more user licenses on this server, we were led to TID 7000769, that states the following:

--------------------------------
To install a new unlimited license into a tree where stratified NetWare licenses already exist, there are a couple steps to follow:

If you have only one version of the NetWare operating system in your tree (i.e. NetWare 6.5 servers only), you will need to first remove all stratified licenses, this includes both user and server licenses:

1) Load iManager (https://ip address/nps/servlet/webacc).  
2) Select Licenses
3) Select Delete a License
4) Browse for a license and delete it. All previously installed licenses, both user and server, need to be removed. The new unlimited licenses cannot coexist in the tree with stratified licenses.

If you have a mixed tree, you will need to remove all stratified licenses for whichever operating system your additional user licenses entitle you to. For example, let's say you have several NetWare 5.1 servers with licenses that service 250 users, a couple NetWare 6.0 servers with licenses for 100 users, and several NetWare 6.5 servers with 500 user licenses. You just ordered and received a quantity of 1-User licenses for NW6.5. You received a certificate for those users and an unlimited NW6.5 license.  You do not need to worry about the NetWare 5.1 or 6.0 licenses. You will, however, need to remove all licenses for NetWare 6.5 before the unlimited licenses will work properly.

Hint: If you have a large number of licenses to delete, you might want to use the old NWADMIN32.EXE to delete them, as it is much quicker than iManager (which requires that you search for, and delete, one license at a time). However, it is recommended that you do all licenses installations from within iManager.

Now you need to install the new licenses:
1) Load iManager (https://ip address/nps/servlet/webacc).  
2) Select Licenses
3) Select Install a License
4) Click Browse and search for the license file (*.NLF)
5) Select Next
6) Check the box next to the license you want to install (UNLIMITED UNIT NetWare 6 Server LICENSE - SN:xxxxxxxx) and hit Next
7) Then you must browse for the location in the tree where you want the license installed
8) Click Install

You should see a message stating the installation was successful.  In order for the new license to be consumed, the server(s) will need to be rebooted.
--------------------------------

First problem, the server never had iManager installed.  So I proceeded to install iManager, Apache, and Tomcat, and everything else required to run iManager.  This was done successfully.  However, once I try to run AP2WEBUP, it reports "<NLM has terminated; press any key to close screen.>"  The logger screen reports:

--------------------------------
Loading module APACHE2.NLM
  Apache Web Server 2.0.63
  Version 2.00.63   April 25, 2008
  Copyright 2006 The Apache Software Foundation. Licensed under the Apache License Version 2.0.
  Auto-Loading Module APRLIB.NLM
  Auto-loading module APRLIB.NLM
  Apache Portability Runtime Library 0.9.17
  Version 0.09.17   April 25, 2008
  Licensed under the Apache License Version 2.0
Module APRLIB.NLM load status OK
Module APACHE2.NLM load status OK
Use of key SSL CertificateDNS failed
Use of key SSL CERTIFICATEIP failed
--------------------------------

I did some research that mentioned I needed to run PKIDiag.  I downloaded the latest version, switched to fix mode, and this happens:

---------------------------------------------------------------------------
PKIDiag 2.78 --  (compiled Feb 01 2007 17:06:17).
     (Check the end of the log for the last repair results)
Current Time: Wed Aug 19 15:11:38 2009
User logged-in as: admin.OU.
Fixing mode
Rename and create mode
Always Re-key

--> Server Name = '{ServerName}'
---------------------------------------------------------------------------

Step 1  Verifying the Server's link to the SAS Service Object.
   Server '{ServerName}.OU' points to SAS Service object 'SAS Service - {ServerName}.OU'
Step 1 succeeded.

Step 2  Verifying the SAS Service Object
   SAS Service object 'SAS Service - {ServerName}.OU' is backlinked to server '{ServerName}.OU'.
Step 2 succeeded.

Step 3  Verifying the links to the KMOs
   Reading the links for SAS Service object 'SAS Service - {ServerName}.OU'.
--> No KMOs are linked to Service object 'SAS Service - {ServerName}.OU'.
Step 3 succeeded.

Step 4  Verifying the KMOs
Step 4 succeeded.

Step 5  Re-verifying the links to the KMOs
   Reading the links for SAS Service object 'SAS Service - {ServerName}.OU'.
--> No KMOs are linked to Service object 'SAS Service - {ServerName}.OU'.
Step 5 succeeded.

Step 6  Creating IP and DNS Certificates if necessary.
--> Number of Server IP addresses = 2
--> The default IP address is: 10.0.0.2
PROBLEM: A SSL CertificateIP does not exist
FIXING: Creating SSL CertificateIP (10.0.0.2)
Pausing for 5 seconds because of error 49695
ERROR 49695 creating SSL CertificateIP.
--> Number of Server DNS names for the IP address 10.0.0.2 = 1
--> The server's default DNS name is:
      ns1.aisn.net
PROBLEM: A SSL CertificateDNS does not exist
FIXING: Creating SSL CertificateDNS (ns1.aisn.net)
Pausing for 5 seconds because of error 49695
ERROR 49695 creating SSL CertificateDNS.
Step 6 failed 49695.

Note: Occasionally multiple problems will be solved with a single fix.

Fixable problems found:     2
Problems fixed:             0
Un-fixable problems found:  0
--------------------------------

Now I am at a dead end.  Any help will be appreciated.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-08-19 at 14:15:42ID24666417
Tags

netware

Topic

Novell Netware Network Software

Participating Experts
2
Points
500
Comments
5

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. SSL and Tomcat !!!!!
    how do i run my tomcat with ssl , so that i can run tomcat with https://localhost/
  2. tomcat + ssl + apache + windows
    hello, i have already installed apache 1.3.24 with ssl on windows 2000 server as described in http://tud.at/programm/apache-ssl-win32-howto.php3 this works fine.now i need to install tomcat on the same server so that servlets can be called with https requests. i would like to...
  3. setting up apache/tomcat with ssl
    Hello, This is more of a Design question. And I would appreciate any help/pointers. At my company we have an AS/400 backend. All PCs in the company are on Windows network. I am setting up a web application which gives an interface to our clients to access thier information ...
  4. Apache, Tomcat, and SSL
    Hi Experts, Let's say that I am using Apache as a web server and also using tomcat to serve the dynamic content using the AJP connector. I have a loginpage.jsp which needs to be run on SSL. My question is where shall I do my SSL configuration? At Apache or tomcat or any of ...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: deroodePosted on 2009-08-19 at 23:53:40ID: 25139811

You can add and delete licenses with Nwadmin32 (sys:\public\win32\nwadmn32.exe)

Problems with certificates can often be repaired by reinstalling Certificate server. On the server console, select install from the GUI start menu, and make sure your NW65 CD is mounted.

 

by: 2mrchioPosted on 2009-08-20 at 09:26:40ID: 25144412

Based on the TID mentioning

Hint: If you have a large number of licenses to delete, you might want to use the old NWADMIN32.EXE to delete them, as it is much quicker than iManager (which requires that you search for, and delete, one license at a time). However, it is recommended that you do all licenses installations from within iManager.

plus the fact that I have to remove the user and server licenses before attempting to install the new licenses (no idea where the current licenses are stored) I'm wary of using NWAdmin when iManager was recommended.

 

by: deroodePosted on 2009-08-20 at 23:53:01ID: 25149581

Is your server Trustee of the Security\KAP\WO object?

Did you reinstall Certificate server?

 

by: ErekoseHPosted on 2009-08-21 at 10:32:44ID: 25153959

I have done this procedure in the past and I want to know a few things.
How many servers in your tree? This does not sound like you are on the license certificate server server if you are getting this problem. You can use nwadmin32 but imanager lets you see things in a different way and Novell prefers that way, since the objects you are looking at don't have schema extensions for NWadmin. Check and make sure of trustee rights etc. Also I am getting confused by your question. If you issued your own certificate and they expired, which happens, then you don't need to reinstall client licenses. You could use console one to get to the server SSL and SAS objects and delete the certs associated with the server from the tree.

Run PKIDIAG from the sys:system of the server in question, as admin. Choose option 4 which turns on fix mode. Then choose 0 to run. All errors should be fixed. Repeat procedure till you get no errors.
If you can remote in now then life is good. If not then you made need to reset the server or the stack. NILE.NLM, HTTPSTK.NLM, and PORTAL.NLM.

 

by: 2mrchioPosted on 2009-08-26 at 15:14:41ID: 25192835

First, deroode I did not reinstall the server but did try to reinstall the certificates, and was unable to do so. regrettably I don't recall the exact error message.

ErekoseH, there are two servers in the tree.  I was in a position that we had 100+ users and only 90 client licenses.  I was told that the license file on the NW65SP8 overlay CD had the proper license to achieve this, but all current server and user licenses need to be removed first.  Since I needed it done days before I posted this request, I held my breath and did it using NWAdmin.  It worked.  However I still do not have iManager installed/configured properly.  Since it is a server at a customer, I will wait until they really need it working to bring up the topic again.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...