Several clients that connect to the same user via the SSL protocol

It's possible? I can't find any documentation about it. Essentially, because of the way our system has been designed, connect us the two our system and our front-end web server to the same processing back-end user. Now, we have an obligation to use PKI/SSL to connect users.

I have experimented with OWM and the TCPS, and was finally able to get a connection between Client1 and the server a user to test called PKI_TEST. The problem is that I get an ORA-28860 error when I try to connect Client2 to the server to the same user. I tried to import the Client2 certificate into server's wallet, but which is perhaps the origin of the problem. So here are my thoughts/questions.

1. how to import the client certificates in the server with the same CN wallet? Seems to be a 'no', but maybe I am doing something wrong.

2. can I import certificate user of Client1 Client2 portfolio so Client2 performs authentication by using the same certificate that worked for Client1?

3. can I copy portfolio of Client1 to Client2 so Client2 uses the same portfolio that has worked for Client1?

4. can I associate a single user with multiple CNs for the client certificates will be different in the wallet of server?

Any help would be appreciated.

Hello

You can just copy the client1 client2 on portfolio, so the client2 can connect / authenticate over SSL to the same DB user.

Tags: Database

Similar Questions

  • Problem with USB auto connect with clients that connect through the Security server...

    Lack of VMware View 5.0.1 with 2 servers connection and a security server. When the clients connect directly to the server connection, USB connection works very well... users can use their USB drives and other devices with their VM. The problem occurs when they attempt to use their USB devices when negotiated through the Security server.

    I know that port 32111 (TCP) must be open between the server security and the connection to the server, but even after doing so it does not always work... customers just to get the scrolling message of office in the USB menu initialization.

    Our current facility is:

    External IP address-> DMZ (Security Server)-> connect to server

    Entrust us our firewall config through our ISP (we are not overloaded with scientists here, it's just me, so things like little help my work load). They are certainly not incompetent (or at least were not in the past). I had to open the external 32111 IP port to the DMZ, then of the DMZ to our connection server that is used for external connections. Everything about VMware View works perfectly for the clients that connect this way, but not USB devices.

    One thing I give is if our having a configuration of VLAN dedicated for customers views influence what either. I'm trying to keep an eye on what ports are open that for our firewall for my records, but I do not see where I openly opened ports on the internal side of security server to our internal network. He must have the port opened directly from the internal face of security server of vmware 32111 discovers clients?

    The firewall Guys tell me that they checked over and over that port 32111 is open throughout the. They also said that they tried to telnet 32111 to our security server port and have nothing back (should have gotten garbage at least according to them).

    An idea of the next steps to take? It is obviously a blocked port, I just have no idea why at this stage.

    I know that port 32111 (TCP) must be open between the server security and the connection to the server, but even after doing it still does not work

    This is not what it takes. The agent is listening on the port 32111, you must open the firewall to allow connections to the Security server for the desktop on port 32111 (same thing you must allow RDP and PCoIP).

    Mike

  • I am trying to download Adobe Premiere Pro cc that I download the free trial version of double click on the installer of creative cloud she gets up and wants that connect you using a user name and password? I never remember to do all an account, I had to

    Hey its jake here

    I am trying to download Adobe Premiere Pro cc that I download the free trial version of double click on the installer of creative cloud she gets up and wants that connect you using a user name and password? I don't remember all account, I had to do when I connected to Adobe was the first and last name.

    you need an adobe (valid email) ID / pass to download the application of office cc, https://creative.adobe.com/products/creative-cloud

    don't forget either.

    When installing on a mac, you will be prompted for the password of your mac.

  • How to force the client to connect to the specific access point?

    I have a client that connects to an Access Point to the upper floor.  The connection is "Very low" and pings are restless.  Is there a way to force the client to connect to the point of access on its own soil in the hallway.

    Access Points using 1131AG; WLC2106

    PSK + WPA2

    Thank you

    There is not a way to force the client to use a specific side access point controller of things.  According to the specifications, the client decides when and where to associate.  You can try to disable some of the rates below data or lower power tx of the AP to reduce the coverage of each access point cell.  By doing this, the client cannot see the other as favourable AP.

  • English (Singapore) on Window XP SP3 - CRM outlook client cannot connect to the CRM system

    original title: English (Singapore) on Window XP SP3

    We have an error on the CRM. CRM outlook client cannot connect to the CRM system. This question because of the language English (Singapore). We cannot locate region & language English (Singapore) on Window XP SP3.

    Hello

    ·         Do you have English (Singapore) installed on the system?

    ·         What exactly are you trying to do?

    ·         What is the exact error message, are you trying to change the system language to English (Singapore) or what?

    ·         What version of the Microsoft CRM client is installed on the system?

    To access the parameters of language and the region on the system, I suggest you to check the below link.

    Regional and Language Options overview

    http://www.Microsoft.com/resources/documentation/Windows/XP/all/proddocs/en-us/int_pr_custom_workspace_regionalsettings.mspx?mfr=true

    I suggest you to post your query in then the link mentioned below.

    https://community.dynamics.com/product/CRM/f/117.aspx

  • VSphere Web Client cannot connect to the server vCenter Single Sign On.

    I'm running the virtual appliance of the trial 5.5.0.20400 build 2442330 on ESXi 5.5.0, 2068190

    While I try to log on to the Web Client, I get this error.  VSphere Web Client cannot connect to the server vCenter Single Sign On.

    I put fallow the steps to disable SSO by changing the webclient.properties line add file and ad sso.enabled = false .    Then on the vCenter Server Appliance, restart the vSphere client service by typing service vsphere-client restart .

    I enclose the reference files.

    All ideas will be useful


    This answer was simple, all I had to do was remove the # in front of the statement in the file.   and SSO has been disabled after the restart of the service.

  • Ideas re: ' Connect-VIServer: could not connect using the requested protocol "failure

    I know, it's a matter of weakness, but I hit the wall on this one. I've even got desperate enough that bouncing private LuD, and I tried everything we discussed, but I'm still @ deadlocked.

    I developed and tested several scripts that I am finally ready to go with Prod.

    I get this error when I am trying to connect to Vcenter server or host of the cmndline of vitoolkit (and obviously in scripts).

    «Connect-VIServer: could not connect using the requested protocol.»

    I'm runing the vitoolkit FROM the server VCenter, so I wouldn't exepct the local to be a problem connection. I expect calls the ESX servers as questions) (we have several firewalls in the game). But even once, on-site I would not expect a problem.

    I checked my ports of VC and even more precisely called listener in the connect command, but it does not help.

    I tried to watch the ports through various lines of command, but I don't see anything.

    Any suggestions?

    Add - confirm: $false and it won't be quick.

    =====

    Carter Shanklin

    Read the PowerCLI Blog
    [Follow me on Twitter |] http://twitter.com/cshanklin]

  • BlackBerry, call web services via the SSL protocol

    Hi guys,.

    We are developing an application BlackBerry to OS 4.1 and we test it on the 8330.  This application calls several web services on a remote server via the SSL Protocol (side).  There is a valid certificate from Entrust installed on the remote server - it works properly with all major desktop browsers.  The certificate has not been installed on the BES - is it necessary?  Some BlackBerry devices will be linked to a company BES, others not.

    When the application calls the web service, a window opens with the following message: "you try to open a secure connection, but the server certificate is not approved."  Continue to push works fine, but the window opens again a few moments later.  Pushing view certificate indicates that the certificate is considered invalid ('unverifiable Cert chain').  The same information is given when you navigate to the certificates of the aircraft.  Certificate trust pushing watch a 2nd window asking you the key Store password, which we are not aware of.

    You guys can help us with this?

    Thank you!

    We have solved the problem.  It seems that the BlackBerry device is having a hard time with a certificate signed by the Entrust 2048 bit root certificate.  Give us a new intermediate certificate signed by their 1024-bit root certificate, which we have installed on our Apache server.  While the window 'certificate is not approved' arises at once, pushing "Continue" worked and it never came up again.  To do this, it will probably install the certificate on the BES, something we don't have yet.

    Thank you for taking the time to answer!

  • Problem with JMS via the SSL protocol in clustered environment

    Hello

    We run Weblogic 11 g Cluster (area) which consists of admin server and two managed server MS1, MS2.
    LIKE and run it on the computer 1, MS1 MS2 runs on machine 2. Both machines have two network interfaces, a public used for client connections and an intern for cluster communication, monitoring etc. The default channel of each Weblogic Server is listening on the internal network interface, and Moreover we have two channels (for http and t3 Protocol) configured to the public interface.
    The two managed servers are JMS provider and there is a JMS Module myModule in the field with the following JMS resources: custom connection factory myConnFactory (Load Balancing active = true = false server affinity, target: entire cluster JMS) and myQueue, which is a uniform distributed queue (targets: MS1, MS2). The queue is accessed by its logical JNDI name, but she is stuck on each managed server.

    JMS communication flows normally through t3 dedicated listening on the public interface. However, a new external client will send messages to myQueue and communication must be encrypted for security reasons. For this reason, we have implemented SSL. Instead activate a DefaultSecure channel, we left 'SSL listen Port active' = false (as the default channel would be linked to the internal network interface) and created a new channel T3SChannel t3s Protocol on the public interface for incoming client connections.

    The customer creates a t3s connection to the cluster (through T3SChannel) and gets the factory connections and the queue, use the JNDI ( source) search. The JMS connection is in real-time with MS1. If we want to create two consumers for this queue, the consumer of fist is created the MS1 and the second will be created on MS2 (thanks to active balancing). However, the creation of the second consumer fails with an exception (it is thrown on the client):

    java.rmi.ConnectException: no valid port known for: "DefaultSecure [t3s]: t3s (t3s): mserver1 - internal .company .com: 56213:null:-1 ';" No router available at destination
    at weblogic.rjvm.ConnectionManager.bootstrap(ConnectionManager.java:464)
    at weblogic.rjvm.ConnectionManager.bootstrap(ConnectionManager.java:396)
    at weblogic.rjvm.RJVMImpl.ensureConnectionEstablished(RJVMImpl.java:303)
    at weblogic.rjvm.RJVMImpl.getOutputStream(RJVMImpl.java:347)
    at weblogic.rjvm.RJVMImpl.getRequestStreamInternal(RJVMImpl.java:610)
    ... 18 more

    We were told that the exception can be avoided with t3s < default protocol > - < / default protocol > element (default is t3) added to the config.XML in the Weblogic domain. If we configure t3s as default protocol, we also need to activate the DefaultSecure channel on each server and then everything works and the customer is able to correctly create consumers.

    However, as a side effect, the entire cluster on weblogic.rjvm communication layer and then by t3s. We do not want that because internal cluster communications are set enough with other methods and it will have impact on the notable performance in the production environment. In principle, it should be possible to enable the external client to connect to the JMS provider via the channel new, safe, without affecting the existing internal communication in the cluster (which should be a black box for the customer).

    My question: is it possible to run the example described without defining the default protocol to t3s?

    Thanks for the reply.

    My question: is it possible to run the example described without defining the default protocol to t3s?

    Thanks for the very clear problem description. I checked with our customer support guru and I'm sure that the answer to your question is no, I think you have encountered a known problem and have already struck with the recommended workaround.

    That said, you can be able to avoid at least partially the problem by setting "server-affinity = true" on your CF. as you probably well know, affinity = false encourages consumer and producer traffic to route customer, on its server host connection, then possibly on a "second leap" to another server in the cluster. It looks like the attempt of an implicit downgrade of a secure request origin SSL in the first bond on a channel not secure in this second jump is to throw the exception.

    HTH,

    Tom

  • How to get the JSP to transmit a request via the SSL protocol?

    I'm new to JSP and servlets, although I worked with Java for a long time. I am writing a registration system and connection of single user to teach myself JSP. I want to put things up so that the user is able to connect securely over https. I don't know how to do this, however. There seems to be no place in the relative URLS to indicate that you must send a request via the SSL protocol. I've got sample page to login below - someone knows how to change it so that it happens safely?

    Also, do I need to install a certificate on my web server?

    index.jsp
    <html>
        <body>
            <h1>Index</h1>
            <a href="login.jsp">Login</a>
        </body>
    </html>
    Login.jsp
    <%@page contentType="text/html" pageEncoding="UTF-8"%>
    <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
       "http://www.w3.org/TR/html4/loose.dtd">
    
    <html>
        <body>
            <h1>Login</h1>
    
            <jsp:useBean id="userLogin"
                         class="com.kitfox.webrpg.UserLogin"/>
            <jsp:setProperty name="userLogin"
                             property="*"/>
    
            <%if (userLogin.isValid()) {%>
            <jsp:useBean id="userId"
                         class="com.kitfox.webrpg.UserIdent"
                         scope="session"/>
            <jsp:setProperty name="userId" property="*"/>
    
            <jsp:forward page="index.jsp"/>
    
            <%} else {%>
    
            <form action="login.jsp" method="post">
                <fieldset>
                    <legend>Enter login information</legend>
    
                    <label for="login">Login</label>
                    <input type="text" name="login" value="${userLogin.login}"/> <br/>
    
                    <label for="password">Password</label>
                    <input type="password" name="password"/> <br/>
    
                    <input type="submit" value="submit">
                </fieldset>
            </form>
    
            <%}%>
        </body>
    </html>

    The first step would be to install an SSL certificate on your web/application server and ensure that it works.

    You can add something like the following to your web.xml file to automatically switch to https

    
      
        Secure Login
        /login.jsp
      
      
        CONFIDENTIAL
      
    
    
  • Custom problem race workspace via the SSL protocol

    Hello

    If we try to run our workspace personalized via the SSL protocol, we get the following in the trace error message: * took place an error event: an error occurred during initialization of workspace. (ALC-WKS-007-049)

    So the stuff of successful connection... but then the error occurs while initializing the workspace .

    In the trace you can also see, that service of the workspace still tries to connect via http, but with the secure port: http://xxx.xxx.xxx.xx:8443 / work-server/messagebroker/amfpolling space

    When we use the Internet-Explorer, the problem only occurs on the first connection. The second time everything works fine.

    Unfortunately, we cannot solve the problem when you use other browsers (Firefox, Safari. Etc.)

    It would be great if someone could give a clue.

    Thank you!

    We use the next version of livecycle:

    Version: 8.2.1, GM

    Patch Version: SP2

    Service Pack Version: 8.2.2353.1.195587.2

    Trace debugging:

    -Built in 3729ms AuthenticatingApplication.

    -called createComponentsFromDescriptors to 3761ms.

    [SWF] /xyz/workspace-theme.swf - 496 567 bytes after decompression

    Finished loading the theme to 3997ms.

    -init called 3998ms.

    Workspace created string: id = work-survey-amf space, url = https://192.168.196.60:8443 / work-server/messagebroker/amfpolling space .

    -checkLogin-

    singleSignOn: SSO connection

    login: https://192.168.196.60:8443/um/login time = 4053 Ms

    an error event occurred: verification of credentials: credentials not found. connection is required. (ALC-WKS-007-149)

    -showLogin to 4240ms.

    [SWF] /xyz/LoadingCircle.swf - 673 bytes after decompression

    -doAuthenticate to 10171ms.

    Login: credentials

    login: https://192.168.196.60:8443/um/login time = 10176 Ms

    sendWorkspaceLogin: https://192.168.196.60:8443 / space work-server/authenticate , time = 10357ms.

    exit sendWorkspaceLogin: https://192.168.196.60:8443 / space work-server/authenticate , time = 10363ms.

    loginHandler

    loginSuccessHandler: time = 10455ms.

    Workspace created string: id = null, url = https://192.168.196.60:8443 / remote/messagebroker/amf access .

    the authentication expires in 6899; to re-authenticate timer set to 6869 s.

    = initialize()

    handleChannelFault - faultCode = Channel .connect .failed NetConnection.Call.BadVersion: url: ' http://192.168.196.60:8443 / work-server/messagebroker/amfpolling space '

    an error occurred: an error occurred during initialization of workspace. (ALC-WKS-007-049)

    an error occurred: an error occurred during initialization of workspace. (ALC-WKS-007-049)

    -showLogin to 10526ms.

    We had the same problem.  There is a patch for it: http://www.adobe.com/support/products/enterprise/support_knowledge_center_livecycle_ES_ser ver.html

  • ORACLE client to connect to the database without user name and password

    Customer require us to perform a function:
    On the client server that has installed the ORACLE client. They can connect to the database without username and passwod entry.
    Use "sqlplus / as sysdba" can archive database connection.
    Is it possible to change the configuration to do this?

    See if external authentication support,
    http://docs.Oracle.com/CD/E11882_01/network.112/e16543/authentication.htm#DBSEG99842

    Aman...

  • Unstable ACS and AD connectivity when client that connects wireless

    Hello

    I have GBA 5.3 related to Active Directory to Windows 2008 R2. I have no problem combining the two services, but when the client attempts to connect to the wireless network, the ACS with flapped AD connectivity when I tried to ping the AD server when you connect on the wireless. Keep it just ask for credentials to connect to the radio but without success. Based on the ACS logs, Active Directory is inaccessible. I did the test of GBA connectivity, it says test connection succeeded. Connectivity issues only occurs when users try to connect again Setup wireless network. We have another set up with the same configuration but using ACS 5.1, which is currently on the network of production with no problem.

    Anyone encountered this problem? Help, please.

    Kind regards
    MiKe

    Yes, there are a few bugs that are mentioned in the release notes-

    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_system/5.3/release/notes/acs_53_rn.html#wp223113

    However, I recommend that you upgrade to the latest patch, release notes will take steps on how to install the patch as well.

    Thank you

    Tarik Admani
    * Please note the useful messages *.

  • frmcmp cannot compile the modules containing SQL code that connected to the database

    Hello

    I checked several hundred messages of the forum on the net without finding a solution.

    I have a Linux server with 11.1 WebLogics (11 GR 1 material) and FormsRuntime installed.

    I am logged in as root.

    I put all the environment variables based on the values in default.env.

    In addition, I updated TERM and ORACLE_TERM vt220. And TNS_ADMIN to the location of the sqlnet.ora and tnsnames.ora.

    I compiled a simple .pll containing only the following code:

    IS test PROCEDURE

    an INTEGER: = 0;

    BEGIN

    a: = 1;

    END;

    command:

    frmcmp_batch module = TESTLIBPLAIN.pll userid=myuser/mypassword@mydb module_type = LIBRARY output_file = TESTLIBPLAIN.plx compile_all = Yes = Yes = No. batch connection

    result: successful compilation. generated .plx.

    now, I'm trying to compile an another .pll containing just the following code:

    IS test PROCEDURE

    an INTEGER: = 0;

    BEGIN

    Select 1 in the doubles.

    END;

    command:

    frmcmp_batch module = TESTLIBSQL.pll userid=myuser/mypassword@mydb module_type = LIBRARY output_file = TESTLIBSQL.plx compile_all = Yes = Yes = No. batch connection

    result: error:

    "

    11 forms (form of the compiler) Version 11.1.1.3.0 (Production)

    Copyright (c) 1982, 2010, Oracle and/or its affiliates.  All rights reserved.

    Oracle Database 10g Enterprise Edition Release 10.2.0.1.0 - Production

    With partitioning, OLAP and Data Mining options

    PL/SQL Version 11.1.0.7.0 (Production)

    Oracle V11.1.1.3.0 - Production procedure generator

    Oracle virtual graphics system Version 11.1.1.3.0 (Production)

    Oracle Multimedia Version 11.1.1.3.0 (Production)

    Oracle tools integration Version 11.1.1.2.0 (Production)

    Common tools Oracle area Version 11.1.1.3.0

    Oracle CORE Production 11.1.0.7.0

    Compile the library TESTLIB.

    Invalidate the body TEST procedure...

    Compilation of body TEST procedure...

    ERROR on line 5, column 1 0

    Ignored SQL statement

    Library TESTLIB closing...

    Errors on TEST:

    PL/SQL ERROR on line 5, column 1 0

    Ignored SQL statement

    Could not generate the library.

    FRM-30312: unable to compile the library.

    "

    the two libraries differ by having used SQl commands or not.

    I tried to compile some more complex .pll and .fmb containg the SQL code. I get similar error messages. The messages that I receive for each module are the same, I would get when compiling the module with FormBuilder 9i (Windows) without being connected to the database.

    So my first thought was, this frmcmp_batch is unable to connect to the database.

    BUT:

    From frmcmp_batch with an invalid user, password, or database name not existing (resp. not in tnsnames.ora), results in appropriate error messages (not found TNS, refusal to sign etc.).

    With myuser/mypassword@mydb I don' t get this kind of messages.

    sqlplus myuser/mypassword@mydb works.

    myuser can access all objects in the database mydb.

    mydb tnsping works.

    When I check v$ session on mydb while (!) frmcmp_batch is running, I see that it is in fact a db session, created from myuser: DB-User = myuser, terminal = myappsever, osuser = root, remote process = frmcmp_batch.  And State of the current session of the db is ACTIVE.

    As a result, frmcmp_batch fails with error messages that I expect that when there is no connection to the base, if it is connected!

    Any ideas what could be wrong with my setup?

    Help appreciated.

    Jean

    I found the solution. Seems, fmrcmp 11g can connect to, but compiles not on the 9i database. With the help of a Database 11 g resolves the problem :-)

  • USB redirection works with a view Windows Client that connects to a Pool of RDS running Server R2 2012

    I installed the Agent view Horizon (6.0.0) and direct view connection Plugin (6.0.0) on a physical server running Windows Server R2 2012 with desktop Services remotely active.  I would use the USB redirection from the client to the server.   When I connect to the remote desktop session by using the Windows Vista client, he tells me that the USB redirection is disabled.   I tried connecting the View Client to the server view connection and directly to the RDS Server with the same result.  I need to activate RemoteFX on the Windows Server running RDS for USB redirection to work?  I don't have any hardware remotefx, that's why I have not yet tried.

    USB redirection is not supported on the RDS (2008 or 2012) guests in Horizon 6.0.

    see you soon

    peterB

Maybe you are looking for

  • HP ZBook 17: Evolution of Windows operating systems

    When I bought the HP ZBook, I opted for the operating system Windows 7 on Windows 8 (he had a choice).  Now, I would like to change to Windows 8.  I have the Application and Driver Recovery DVD for Windows 8.  As a side note, last weekend I spend Win

  • How updgrade OS 10.6.3

    Hello I had an older version of MAC OS 10.6.3 running now for many installations I do it tells me to upgrade my software upgrade should be, my cell phone yosemite "handles," but its very slow and I just don't want to go back. Then I reinstalled the f

  • HP Officejet Pro 8500 a Premium: HP sides selection (duplexer) printing accessory not preserved

    I use OS X Yosemite (version 10.10.3).  June 19, 2015, I've updated the printer HP Software Update (version 3.1).  System Preferences > Printers & Scanners > Options & supplies > Options, select the accessory of HP print two-sided (duplex unit).  My

  • The fan runs continuously

    I had this problem for a few weeks and I don't know why. The fan on my Dell laptop starts to run as soon as I turn it on and it does not stop. My son cleaned it out to ensure that it is not full of dust, but that has not changed anything. the compute

  • Windows Vista, internet explore 7 error msg "internet explore has stopped working".

    Intermittently, I get this error msg when it either wont connect or is slow in doing so. This happens NOT all the time. I seem to be able to move things again by closing & then start-up. I use internet explorer 7 on a laptop DELL inspiron 1525. Equip