[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

Question
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

9.3

! symbol and "Limited External Calling" error in OCS this morning

Asked by drhixson in Live/Office Communications Server

Hmm, not sure if that error is a red herring or not.

Doing a little more digging, Ive found an error in the Office Communications Server log 

Category: 1043
Event ID: 19007

A/V Authentication Certificate used for generating credentials not found in the machine store or it may be invalid. A/V Authentication Edge Service will stop.

Certificate Serial Number: '06DC814EF1444848B3E576073AC88689' Issuer 'CN=DigiCert High Assurance CA-3, OU=www.digicert.com, O=DigiCert Inc, C=US'
Cause: A/V authentication certificate was not found in local machine store or it is invalid
Resolution:
Install the certificate into local machine store and check if the config parameter has the correct serial number. If the certificate was found, check if it is valid.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Which is then followed by an error that says:

Category: 1043
Event ID: 19005

A/V Authentication Edge Service could not be started.

Exception: Microsoft.Rtc.MRAS.MRASException: server sharedsecret certificate not found in the local machinestore
   at Microsoft.Rtc.MRAS.Crypto.GetValidCertificate(String issuerName, String serialNumber, Boolean isBankCert)
   at Microsoft.Rtc.MRAS.Crypto..ctor(Byte[] bankCertSN, Byte[] bankCertIssuer)
   at Microsoft.Rtc.MRAS.CredentialsGenerator.InitializeCrypto()
   at Microsoft.Rtc.MRAS.CredentialsGenerator..ctor(Configuration config)
   at Microsoft.Rtc.MRAS.Core.Initialize()
   at Microsoft.Rtc.MRAS.Core..ctor(ServiceStopHandler serviceStop)
   at Microsoft.Rtc.MRAS.Server.OnStart()
Cause: Internal error.
Resolution:
Examine the details in the associated event log entry to determine the potential cause and report to Product Support Services.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

All of which would seem to indicate the server either cant find the DigiCert UC certificate on this box (which wasnt due to expire until 2/2011), or it cant use it anymore.

However when I look at the cert chain for the UC cert on the box, everything looks fine (see attachment)

(And yes, I checked all of the certs above this in the chain, and they all check-out.)

Now I grant you that Ive never installed a UC cert myself, but I dont see any problems here that would explain our issue.

At present Im just poking-around, trying to find anything on Google that might shed some light on all of this, so if anyone has a brilliant idea, Id be very glad to hear it.


Attachments:
 
screen shots
 
[+][-]09/14/09 04:28 PM, ID: 25330204Accepted Solution

View this solution now by starting your 30-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

About this solution

Zone: Live/Office Communications Server
Sign Up Now!
Solution Provided By: jayca
Participating Experts: 1
Solution Grade: A
 
 
Loading Advertisement...
20091111-EE-VQP-92 - Hierarchy / EE_QW_3_20080625