Re: Remote Web Workplace Stopped Functioning

From: David Southern (perfection97_at_hotmail.com)
Date: 04/05/04


Date: Mon, 5 Apr 2004 11:35:44 -0400

When I changed our certificate, I found that I had to go into add/remove
components and make sure certificate authority was enabled.

by default after the original is created the local authority was not
"enabled" on the server so all the subsequent certificates are not ready for
useing.

Just a shot.... but check it out and see if it works for you, then install
the new certificate made by the enterprise certificate authority on both the
SBS and inside the ISA server. They do have to match and no two
certificates should be the same, even if all the events were the same for
their creation.

"Jim Clark" <jimandstephanieclark@hotmail.com> wrote in message
news:O4nGpXxGEHA.1368@TK2MSFTNGP11.phx.gbl...
> I have some additional information. When a users tries to connect to RWW
I
> get two errors in the event log:
>
> Source: crypt32
> Event ID: 8
> Failed auto update retrieval of third-party root list sequence number
from:
>
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/
> en/authrootseq.txt> with error: This operation returned because the
timeout
> period expired.
>
> and
>
> Source: Microsoft Web Proxy
> Event ID: 14200
> ISA Server failed to establish an SSL connection with
> publishing.ChildPlus.local. The certificate chain was issued by an
authority
> that is not trusted.
>
> Does this help?
>
>
> "Jim Clark" <jimandstephanieclark@hotmail.com> wrote in message
> news:#GshSLnGEHA.684@tk2msftngp13.phx.gbl...
> > I have an SBS 2003 Premium server and we are using ISA Server. I set up
> SBS
> > on a new server back in February and it has been working pretty well for
> us.
> >
> > I recently had a problem enable VPN via the Remote Access Wizard.
> > Eventually I figured out that our OU had been changed from MyBusiness so
I
> > changed it back and the RAW ran without problems.
> >
> > A few days ago I began to see errors like this in the Application Event
> log:
> >
> > Source: SmallBusinessServer
> > Event ID: 5120
> > An error occurred in the function
> DeleteUnsafeAttachments:IBodyParts->Delete
> > while running the Secure Attachments Tool (Secatts.dll) to remove SMTP
> > e-mail attachments. The error code is: -2146644475. To fix the problem,
> run
> > the Configure E-mail and Internet Connection Wizard, and clear the
option
> to
> > remove e-mail attachments; then run the wizard again and select the
> option.
> >
> > Silly me ran the CEICW and noticed that the certificate I created used
our
> > domain name (domain.com) instead of our machine name
(server.domain.com).
> I
> > changed this and the wizard failed while configuring the "Security Web
> > Site". When attempting to connect to RWW the certificate is presented
but
> > after accepting it ISA reports the following error:
> >
> > 500 Internal Server Error - The certificate chain was issued by an
> authority
> > that is not trusted. (-2146893019)
> > Internet Security and Acceleration Server
> >
> > I have spent quite a bit of time working with this to no avail. I have
> been
> > tempted to muck around with certificate authority on the server but
> > generally consider it a mistake to manipulate this stuff directly on an
> SBS
> > server.
> >
> > Can anyone offer some suggestions for troubleshooting this issue?
> >
> >
>
>



Relevant Pages

  • RE: Help with Internet and Email wizard
    ... Thank you for posting in the SBS newsgroup. ... On SBS Server, run the CEICW, go through "Connection Type" page, on ... Since we don't want to set up an external internet access, ... We can select Option one "Create a new Web server certificate" to ...
    (microsoft.public.windows.server.sbs)
  • RE: ActiveSync and T-Mobile Treo 650
    ... Thank you for posting in the SBS newsgroup. ... Generally, to publish ActiveSync, you just need to run the CEICW and enable ... Method 2 - Replace your Exchange Web Publishing rule with a Server ... new certificate on the Exchange server to match the new url being used to ...
    (microsoft.public.windows.server.sbs)
  • Re: Outlook RPC over HTTp deosnt work
    ... Certificate, click Install Certificate, and then follow the instructions. ... when you try to use RPC over HTTP to connect the Exchange Server. ... In SBS 2003, we don't have to manually configure RPC over HTTP. ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS2003 + .local domain = no ActiveSync?
    ... I have created a Forward Lookup Zone in our SBS DNS and created the appropriate Host records as suggested elsewhere in this thread. ... However, I still have certificate problems, with WM5 on the Qtek device telling me that the certificate on the SBS is invalid. ... Actually disabling SSL on the server DOES help - ActiveSync works fine if SSL is not required. ...
    (microsoft.public.windows.server.sbs)
  • Re: Outlook RPC over HTTp deosnt work
    ... Certificate, click Install Certificate, and then follow the instructions. ... when you try to use RPC over HTTP to connect the Exchange Server. ... In SBS 2003, we don't have to manually configure RPC over HTTP. ...
    (microsoft.public.windows.server.sbs)