Hi,
I have installed OCS 2007 EE following a few guidelines, but experiencing problems when validating the install - and I'm wondering if it may be related to a certificate issue.
The Web Components Server Functionality test runs ok, but when running the Audio/Video Conferencing Server Functionality test it fails at some points like the error below (all tests related to port 444 fail).
domainname.suffix replaces original domainname.
MCU Type: audio-video
URL:
https://ocspool.domainname.suffix:444/LiveServer/MCUFactory/HTTP Connectivity Error : ReceiveFailure
HTTP Connectivity Error : Receive failure typically indicates that the connection was closed by
the remote host. This can happen if the remote server does not trust the certificate presented by the
Local Server.
HTTP Connectivity Error : Ensure that the certificate of the local server and remote server are both
valid, have not expired, and contain valid subject name. In addition, ensure that the certificate chain
of both Server(s) are valid. Ensure that the certificate chain of the local server is installed
on the remote server and vice-versa. The most up-to date certificate chain that was used to issue
the server certificate must be present.
As far as I can tell, all tests running against port 443 validate the certificate without problems.
There is no firewall between myself and the server (running test locally, disabled Windows FW and antivirus client and I've disabled the loopback setting from 2003 SP1 (which originally gave a few more errors).
The certificate is issued to the FQDN alias which was specified as both internal and external FQDN when installing the server, however this is not identical to the servers netbios/hostname.
When someone originally configured the company domain, they used the public domain name (thanks...), hence using the same FQDN for both internal and external purposes.
I also found a reference where this might be a problem with too many CAs, but exported and removed all CAs except those directly related to the OCS server (internal DC CA and external certificate provider CAs), without any change.
If I try to access the URLs in IE, I get a prompt to choose a digital certificate - which is blank.
Anyone got any ideas to help me on the way to getting this running smoothly?
Start Free Trial