ODSEE 11 g and SSL certificate on the cascade replication topology

Hi all

I try to activate SSL on the replication topology cascade Department 11g with 4 cases including 1 hub.

Can I use a multi server SSL certificate to spread on all servers?

Any tips?

Thanks in advance.


Eugene

Hello Eugene,

Yes, it should work.

Either ask a multiple server of your CA certificate and import it on Department via PKCS12

or generate a CSR with a subjectAltName with certutil.

If I remember correctly, add another name of subject certificate is possible on the side this even if it is not present in the request of cert,.

-Sylvain

------

Please check the response as useful or correct when it is appropriate to make it easier for others to find

Tags: Fusion Middleware

Similar Questions

  • Setting the SSL certificate for the web user interface

    How can I configure the SSL certificate for the management of a SG300 interface? I don't seem to find the configuration option in the web gui?

    Hello Dirk,.

    For import / create / modify h99350 ssl please go to ' ' security > SSL server > SSL server authentication settings.

    HTTPS is enabled by default.

    Thank you and best regards,

    Siva

  • SSL certificates on the desktop HTML access

    I am configuring access HTML and try to correctly configure SSL certificates on the VDI desktops in a linked Clone pool.  Documentation, VMware wants us to install a unique certificate for each desktop computer that will be a pain and from what I see, is impossible.  Does anyone have an easy solution for this?  The main problem that I notice, is that the IP Office address is what actually shows in the URL.  How an appropriate certificate can be created with a DHCP address he will change all the time?  Any guidance will be appreciated.

    Connect via a connection or a security server the value "use secure gateway" for HTML.  Only cert is the entry door.

  • ASA5500 - Essentials SSL and SSL Premium on the same platform?

    Hi all

    A make a BOM THAT and I just ask my self can we order on the platform of a single (for rxample 5510-SEC-BUN-K9)

    SSL Essentials license (the license is on the default platform we buy 250 ussers) and I need 50 user licenses them to be Premium.

    Can I purchase a license of thos two on the same platform and this will work?

    You cannot activate the essential SSL and SSL Premium on the same platform. You can't have that 1 or the other, not both.

    Essential SSL will give you that the maximum number of SSL VPN support on the platform, however, only for the complete tunnel mode AnyConnect.

    Premium SSL will give you the number of users purchased, however, it supports all flavors of VPN AnyConnect/SSL, IE: AnyConnect full tunnel mode, WebVPN (Clientless SSL VPN) and all the advanced functionality of SSL VPN.

    I hope this helps.

  • Pre complains about SSL certificate on the exchange server

    Hello.  I just got a pre and tries to set up to communicate with an exchnage server.  Pre complains and will not set up the connection with this error message: «"SSL certificate error.» Is the date and time correct? ».  The date and time are correct, but the server is running a self signed certificate.  This causes no problems with iPhones that use a lot of people here.

    How can I fix it?  It is not all parameters for this problem.

    I spent the weekend trying to test and understand what was going on.  I found that if I nominated the e-mail server (name after HTTPS: / / in Setup) the same as the name of certificate displayed in the Certificate Manager (Launcher > Device Info > more info > Menu > Certificate Manager), the error should disappear.  The problem for me was that the name of cert in cert Manager was different from address of mail server (in my case server. [domain .local] instead of mail. ([Domain_name] .com).  The transformation it seems to use is:

    (1) find the certificate...

    (2) CN is HTTPS: / / in the installer?

    (3) If no, use error 'Verify the certificate, date and time not correct' (or whatever it is) - If Yes, go to HTTPS: / /.

    (4) Exchange requires safety pin?  If no, proceed to synchronize - if so, use error "unsupported of security policies.

    So I looked more closely CERT and it held several common names (CN) for the cert.  It seems that ANY OTHER DEVICE can filter through the list of common names, and use the one that works.  The Pre uses only (whether first or last, I don't know).

    So, there are two options for the certificate problem (I guess the 3rd is that you can return the phone):

    FIRST SOLUTION

    =====================

    (1) check the name of cert in cert Manager.

    (2) if it is a name that can be resolved DNS (i.e.  [mail]. [mywebsite]. [com]) then change this setting in your exchange installation program in the mail server field beside the HTTPS: / /.

    This will only fix it if your COMPUTER administrator has with permissions on the used field.  It is possible that an alias is used on other areas

    SECOND SOLUTION (as I have done)

    =================================

    (1) ensure that your Certification Authority is installed.  You can do it by clicking START > ADMINISTRATIVE TOOLS > CERTIFICATION AUTHORITY - OR - on a computer on your network using IE/Safari/Firefox and typing http://server/certsrv.  If the page is found, then you are installed, if not, then you will need to have installed.

    NOTE: SBS 2003 WILL AWARD A CERT TO THE IIS WITHOUT THE ROOT CA.  THIS SEEMS TO BE THE PROBLEM WITH THE AUTO CERTS GENERATED I HAD

    (2) If you have not installed it, go to this topic, it is well written to get step by step instructions how to install, create demand for cert, create the cert and install the cert (it took me about 30 min).   http://www.MSExchange.org/tutorials/SSL_Enabling_OWA_2003.html

    NOTE: IF YOU ALREADY HAVE A CERT ON IIS, YOU NEED TO REMOVE IT AS IT IS "DEFECTIVE" CERT BEFORE YOU CAN REQUEST A NEW CERTIFICATE.  YOU MAY BE ABLE TO REINSTALL OVER THE NEW CERT, BUT I DON'T KNOW

    (3) open https://mail.domain.com/exchange on your computer - display details of the cert and save the file on your desktop - if you are using a laptop, you can also install it on your laptop to use for use outside the Office (this is also a good back-up that you can use to get more later if needed again).

    (4) plug your pre in USB mode.

    (5) slide the cert and unplug the USB cable

    (6) go to cert Manager

    7) tap on the icon of "Sun" at the bottom left

    (8) press on the new file cert that you save in USB mode

    (9) to confirm that the new cert appears with the name of the correct mail server

    10) go to the e-mail program and configure the exchange account

    The above will create a REAL root cert (not IIS domain root Cert) that the Pre can work with.

    Really, I don't know that how/why Palm overlooked this possibility because they claimed so-called does not want to sell to companies who need strict security requirements.  For me, it means a small / medium company that has limited IT supports (according to the needs, pay as you or green guy with limited knowledge).  Then, why they test the GER in this environment, I'm not sure.  I bet they were tested on their own network, which has all the correct methods, best practices for the management of cert.  I guess it's like the developers that they have offended and almost lost their support until turned it over and said: 'sorry, we really want make you programs for our platform WebOS. ".  We've just been paranoid for so long salivate us when the bell rings. "They just didn't beta test this well enough.  The sad result of this is that Sprint will have to address all of the sheets because this certificate simple reading process was given only minimal recognition capabilities.

    But having said that - I'm now completely in love with my pre!

    I'm happy to try to help if you need it.  I found a lot of the forum of solutions were not enough detailed, so do not hesitate to contact.

  • LabVIEW and SSL certificate

    So I come back on an interesting question that can cause significant problems, unless I can find a reasonable solution.

    Until yesterday a number of software programs that run in a number of remote sites were running all fortunately accessing a database.  This database is accessible via the HTTPS POST and screw HTTPCLIENT, and for the past two years, everything worked fine while having the true flag to check server, the database is part of a site that is all signed and certified.

    However, as of yesterday, they all decide to stop, investigate the server itself it seems that the SSL certificate has switched from the previous period. While browsing the forums of LAVA, I managed to find the reference to the problem with which a LabVIEW ca - bundle.crt file making the obsolete object so not check the validity of the new certificate.

    Now, while there is here a workaround which the server verify the Pavilion from true to FALSE switching, I can do all programs work again, there's the issue of having to update and rebuild several years worth of programs. So I was expecting something that I could do outside of LabVIEW to try to solve the problem, I had considered to replace ca - bundle.crt, but I'm not sure of the validity of this idea.

    So, any ideas are likely to be accepted if they mean that I don't have to go to several versions of LabVIEW.

    TLDR:

    I can do something with it to solve the problem?

    Welll the good news is that I found a solution. The problem is that I don't know to what extent this solution will get me, it should mean at least I can reach the single database I'm targeting.

    Subsequently to the rear since the database certificate (COMODO) provider I found they provide CA bundle which when used to replace the LabVIEW supplied ca - bundle.crt allows the system HTTP access the database without problem.

    For remote computers, it's probably fine as it is guaranteed to have the only secure site SSL they will try to access the database that I know the data are compatible with. For my development system however it may still remain a problem that I don't know when I'll have to try to access another site certified and whether or not the new authority will work. Although in all fairness for the moment I don't know if the LabVIEW provided one or the other will work.

    I might have to come back to this thread at a later date and to make the point about how everything worked.

  • What everyone uses for an SSL certificate on the wireless controller?

    If I use the SSL certificate generated locally on my WLC Internet Explorer always shows the "untrusted cert alert" when users try to authenticate through the web interface. What can I do to fix this do I need to buy a cert? If so where is the best and the best place to do this? GoDaddy? Also, I bought one for my mail server and had set a domain during the process name. What should I use for my WLC? The URL during the authentication process web show https://1.1.1.1

    RapidSSL is your best bet. It is less than $90 for 1 year with renewal and insurance. 5 years is like $ 380. GoDaddy will not work because they use chained certificates.

    On the VIP, you enter the DNS domain name as what you used on the certificate CN when generating a csr. Of course, you have to solve the CN name to 1.1.1.1 or change the 1.1.1.1 to another ip address that is not on your network. Restart the wlc and your done.

  • Help generate the SSL certificate for the Security Server

    Hi people,

    We have server (ss - 01.mydomain.local) security and connection server (cs - 01.mydomain.local). Now intend to install a certificate on the Security server. What should be the common name.

    our Web site is something like access.mydomain.local.

    Also, we plan to install SSL only on security for internet access server, this will affect the internal users, access to the connection to the server.

    Thanks and greetings

    J P Raj

    Take a look at the link below

    https://pubs.VMware.com/horizon-view-60/topic/com.VMware.ICbase/PDF/horizon-view-60-scenarios-SSL-certificates.PDF

    Internal users will not be affected when you install the Security server certificates

    Simply create a CSr file > get certificates and import them to the Security server in the MMC guide explains practically everything. If you already have certificates wildcard certificates, then you can follow the sub process

    (a) export the server certificates

    (1) to connect to the server that has certificates

    (2) for this server to export it to a PFX format certificate.

    (3) open the Microsoft MMC Certificates snap-in for the computer account.

    4) navigate to certificates (Local computer) > personal > certificates.

    (5) right-click on the signed certificate that is to be exported.

    6) click all tasks > export.

    (7) on the Welcome screen, click Next.

    8) click Yes, export the private key.

    (9) if it is an option, click on include all certificates in the certification path.

    (10) enter a password for the private key. This is required for the import certificates.

    (11) to enter a file name and location. For example, C:\certificates\certificate.pfx.

    12) click Next.

    13) click Finish.

    b) import it to the use of broker or planned connection securityr.

    Certificates of thye 1) import (preferable Pfx format) for the server broker or planned connection security.

    (2) open the Microsoft MMC Certificates snap-in for the computer account.

    3) navigate to certificates (Local computer) > personal > certificates.

    (4) right-click the certificates.

    5) click on Import.

    (6) through the pfx and click Next.

    (7) enter the certificate password.

    (8) select Mark keys as being exportable.

    9) click Next.

    10) click Finish.

    (c) restart Consulting Services

    To restart the services:

    Log in as an administrator on the server that is running the Server VMware View connection server VMware View connection or VMware View Server Security.

    Click Start > run, type services.msc and press ENTER.

    In the list of services, right-click on the VMware View connection Server or VMware View Server Security service.

    Click on restart and wait for service to stop and start.

  • vCenter 5.5 Virtual Appliance and SSL certificates

    I currently have vCenter 5.5 under Windows 2008 R2.  I've been thinking to replace my Windows with the appliance vCenter vCenter virtual.

    I have read the documentation on the SSL certificates for vCenter.  I bought a RapidSSL SSL certificate on my current server vCenter.  It seems that everything is working correctly, but the documentation I read says I need a different cert for various services such as inventory, Journal browser and AutoDeploy Service.

    VCenter requires there really that many different certificates?

    Yes, each component of vCenter server requires unique SSL certificate:

    Reference:http://www.vmware.com/files/pdf/techpaper/vsp_51_vcserver_esxi_certificates.pdf

    See also: http://pubs.vmware.com/vsphere-55/topic/com.vmware.ICbase/PDF/vsphere-esxi-vcenter-server-55-security-guide.pdf

  • SSL certificate for the Security Server external facing

    Dear all,

    Today, I bought an external SSL certificate of DigitCert for our security server. I imported the certificates in the personal certificate (computer account) on the Security Server store. DigiCert provided three certificates, root CA, CA server and the other with the name of our domain. I renamed the vdm to the friendly name of the existing self-signed certificate and used the friendly name for the certificate vdm has our domain name. Subsequently, I rebooted consulting on the Security server. They are all released on except the "Display Blast Secure Gateway" service which entered the suspended state.

    On our facility, we have a connection to the server and a security server. To the Security Server, we use a different domain name for connecting to the server. We have an internal PKI and the connection to the server uses an SSL certificate.

    connection to the server = server01.internaldomain.com

    Security Server = server02.externaldomain.com

    Why the certificate cannot be loaded to view Blast Secure Gateway? I missed something?

    Thank you

    Edy

    I solved it. It was with the private key of the certificate. This is the reason that the Blast Secure Gateway could not load.

  • Forms 11 g and SSL certificate...

    Hello:

    Do you know if a simple SSL certificate works with form of oracle 11g? For example comodo or digicert certificates...

    http://www.Comodo.com/business-security/digital-certificates/SSL.php
    http://www.digicert.com/SSL-certificate-comparison.htm

    do they work? Or I need something special?

    Concerning
    Ricardo

    Forms is just an application. SSL applies to HTTP communication. Forms does not really how you make your SSL connection. If you can successfully establish a connection between the client and the server (middle level) with a SSL connection, forms should work.

    So, the question is, ' can you access any content on the client's server through an SSL connection? This must be established before you try to do this with Forms. In other words, can access the home page of Fusion Middleware with a SSL connection?

    https://server:port

    In the above, enter your name of the server and the SSL port number that you are using. If the SSL certificate has been configured correctly, you should see the homepage of Fusion Middleware. If this isn't the case, it's time for troubleshooting. Do not bother playing with shapes at this point.

  • the upgrade to vCenter 5.1.0b and SSL certificates

    someone knows if this minor upgrade will be stomp on the SSL CA (SSO, inventory, vCenter, Crossover, etc.) the certificates that we have thoroughly improved when we went from 4.1 directly to 5.1.0a?

    Thank you.

    Hello

    Your existing certificate will be in place while you perform the upgrade to vCenter server and after upgrade too.

    Concerning

    Mohammed

  • Bad SSL certificate on the server to dial

    I recently upgraded from 5.2 view see 6.0 and now my composer Cert Server is bad.  Because of this, I can't not recompose pools.  When I try to run sviconfig-operation = ReplcaeCertificate I get an error that says: 'access denied '.  I am currently connected with privileges field and tried different users with the same message.  Can someone tell me how to go beyond this?  Thank you

    Perry

    Do not take into account.  I got it fixed.  Even though I was logged in as an administrator, I had to run elevated command line.  Everything is good.  Thanks for the research.

  • Cannot save vSphere Web Client after the replacement of the SSL certificate

    Hi all

    I have followed the Articles of Derek Seaman on the replacement of all the certificates in vSphere 5.1 and have since turned to the VMware KB Articles. I replaced the certificates for the SSO, the inventory Service and vCenter Server with no problems (other than having to use OpenSSL-Win64 for vCenter certificate that I could not get the x 86 version certificate of work, makes no sense, but I'll take the small victory).

    If you follow the guide of vmware to replace the web service certificate, http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC & docType = kc & docTypeID = DT_KB_1_1 & externalId = 2035010, I get to step 12, enter the VMware vSphere Client Web back to vCenter Single Sign On and the following error:

    ##########################

    D:\Program Files\VMware\Infrastructure\vSphereWebClient\SsoRegTool > regTool.cmd registerService - cert "C:\ProgramData\VMware\vSphere Web Client\ssl" - ls - url ( https://(Server URL): 7444/lookupservice/sdk - username admin@system-domain - password (password) - dir 'D:\Program Files\VMware\Infrastructure\vSphereWebClient\SsoRegTool\sso_conf' - ip "*." ' * ' - serviceId-file 'D:\Program Files\VMware\Infrastructure\vSphereWebClient\serviceId'

    No file properties not found
    Initialization of provider of record...
    SSL certificates for https://vsphere.au.ray.com:7444/lookupservice/sdk
    SSL certificates for https://vsphere.au.ray.com:7444 / sso-adminserver/sdk
    Unhandled exception trying to escape: null
    Return code is: OperationFailed
    100

    ##########################

    VMware technical support suggested I uninstall all components, delete all databases and try again. I have done this and have exactly the same result.

    Has anyone seen elsewhere or managed to solve?

    Chris

    So, I managed to solve this problem. Not sure that this applies to everyone, but my problem was caused by registering using among other names of the subject in the SSL certificate for the SSO rather than the common name of the certificate.

    For example, the server name is server1.company.com. It is the common name of the certificate. But one of SAN of the certificate has been "vSphere.company.com".  If I used this other name in one of the component records that they would fail. I found that I have to use the common name. Even if the alternative names of job access to via your browser web, there is no certificate warning, if the registration of components using these names, it would fail.

    It seems crazy that you can use any of the San... then why allow us to make?

    Initially, I tried to replace the authentication certificate ONLY when the town was called vsphere.company.com, rather than the hostname of the server, and which is installed. However, try to install the Web Client would fail. When you come to the step where you have to accept the certificate of SSO, the installation fails because the common name of the certificate does not have the host name of the SSO server. It seems insane to me... why the host name of the server running the SSO should still come in when all calls are over HTTPS is simply absurd!

    I confirmed this with VMware Technical Support and they checked my conclusions.

  • Update the SSL certificate on a security server?

    Good afternoon everyone,

    I'm trying to update the SSL certificate on the server of our security, but I'm running into some problems.

    DigiCert (we get our certs of), not like the VMWare KB article order to request a 2048-bit crt, so we used their tool to generate our a commandsfor us:

    keytool - genkey-server alias - keyalg RSA - keysize 2048, FULL domain name -.jks keystore - dname 'CN = CNNAME, OR = OUNAME, O = ONAME, L = NAME, ST = STNAME, C = CNAME'

    keytool-certreq alias server-file FQDN.csr - FULL.jks domain name

    (I did not show the exact details of the CN name, etc.)

    It makes the keystore a .jks instead of a .p12

    Should this cause problems?


    Because after I imported the cert in the keystore, change the config locked file to reference the key file and restart the Server Security Service, it does not restart properly. (Defining the locked towards the old works fine keystore file, then restarting the service works find though.)

    This documented error in Event Viewer:

    Not able to create the com.vmware.vdi.ice.server.JMXServer.main(SourceFile:211) MBean server
    javax.management.MBeanException: Exception thrown in the startServer operation
    at com.sun.jmx.mbeanserver.StandardMetaDataImpl.invoke(StandardMetaDataImpl.java:435)
    at com.sun.jmx.mbeanserver.MetaDataImpl.invoke(MetaDataImpl.java:220)
    at com.sun.jmx.interceptor.DefaultMBeanServerInterceptor.invoke(DefaultMBeanServerInterceptor.java:815)
    at com.sun.jmx.mbeanserver.JmxMBeanServer.invoke(JmxMBeanServer.java:784)
    at com.vmware.vdi.ice.server.JMXServer.main(SourceFile:209)
    at sun.reflect.NativeMethodAccessorImpl.invoke0 (Native Method)
    at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
    at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
    at java.lang.reflect.Method.invoke(Method.java:585)
    at net.propero.workspace.windowsinfrastructure.tunnelservice.TunnelService.run(SourceFile:34)
    at java.lang.Thread.run(Thread.java:595)
    Caused by: java.lang.Exception: ice beginning: null
    at com.vmware.vdi.ice.server.Ice.startServer(SourceFile:695)
    at sun.reflect.NativeMethodAccessorImpl.invoke0 (Native Method)
    at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
    at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
    at java.lang.reflect.Method.invoke(Method.java:585)
    at com.sun.jmx.mbeanserver.StandardMetaDataImpl.invoke(StandardMetaDataImpl.java:414)

    Should I request/pay for a new cert so my base keystore is .p12 instead of .jks?

    Hello

    I think that the command you mentioned creating a CSR only. You get a digicert certificate after sending this rea and create a keystore with whom?

    Please follow the steps in this KB to complete the whole process.

    http://KB.VMware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalID=1008705

    -noble

Maybe you are looking for

  • iPad will not update beyond 5.1.1

    bought an ipad, but it will not update beyond 5.1.no matter how many time I restore or attempt to update through itunes

  • laptop password admin or power on password

    did not use computers for a long time. When I finally turned it on this game a black screen with a blue box asking admin password or password running after unsuccessful attempts, he gave me a disabled system code #55146425

  • Blocked loading bar

    I was installing El Capitan on my mac pro when you are connected to the battery and I left the room. When I got home, I saw that he was in the screen of the Apple with the loading at some point bar, but without informing the rest of the installation

  • Cannot install KB2645640 via Windows Update. (error code 80073712)

    Original title: cannot install KB2645640. * error code added to title *. When you run Windows Update I'm unable to install KB2645640 with error code 80073712 marked.

  • Photosmart 3180 prints the worksheet to test each time it is turned on

    Once a black ink cartridge failed, I tried both black cartridges HP no and neither worked and now put in a HP92.  This works.  Since the first wrong cartridge has been the printer prints the complete test page whenever it is turned on.  Is there a wa