+ Reply to Thread
Page 2 of 2 FirstFirst 12
Results 21 to 26 of 26

Thread: Niagara 4 - Server Certificate Issues

  1. #21
    Join Date
    Jan 2003
    Location
    USA
    Posts
    9,437
    Post Likes
    Would like to know what support comes back with.

    Wildcard certs would be my first choice if I had to deal with fully valid certs end to end in a large install. Even if its *.bms.biz.com.

    Our controllers are going to have the option of ssl comms soon. Can't imagine the headache of having individual certs per device. Massive PITA without wildcard certs.
    Propagating the formula. http://www.noagendashow.com/

  2. #22
    Join Date
    Jul 2002
    Posts
    1,790
    Post Likes
    I ran across a good video here https://www.youtube.com/watch?v=jk0F_ZDZg1U

  3. #23
    Join Date
    Nov 2009
    Posts
    213
    Post Likes
    Any updates on this? am running into similar issues with wildcard cert - turns green, but still having access issues

  4. #24
    Join Date
    Jan 2003
    Location
    USA
    Posts
    9,437
    Post Likes
    Little details given.

    You accessing things with IPs or FQDNs? IPs will not work with wildcard certs.
    Propagating the formula. http://www.noagendashow.com/

  5. #25
    Join Date
    Nov 2009
    Posts
    213
    Post Likes
    here is what I am getting in app director:

    WARNING [10:35:09 23-Jun-23 CDT][web] unable to obtain certificate 'umesccowley.iot.usgs.gov' (certificate does not verify with supplied key), trying default

  6. #26
    Join Date
    Jan 2003
    Location
    USA
    Posts
    9,437
    Post Likes
    Would take a look at this.

    https://www.niagara-community.com/s/...curity-warning
    https://www.niagara-community.com/s/...ubleshoot-this
    https://www.niagara-community.com/s/...h-supplied-key

    Tridium is a special snowflake when it comes to certs, especially if they have been created or touched outside of WB. The order of things has to be right or it pukes. Can't say I have seen them turn green and not work after importing them, but looks like that may possible.

    Also would note that a wild card only applies to that level in the FDQN. So a wild card cert for "*.abc.com" is good for foo.abc.com and headbang.abc.com but not deathby.papercuts.abc.com.
    Propagating the formula. http://www.noagendashow.com/

+ Reply to Thread
Page 2 of 2 FirstFirst 12

Quick Reply Quick Reply

Register Now

Please enter the name by which you would like to log-in and be known on this site.

Please enter a password for your user account. Note that passwords are case-sensitive.

Please enter a valid email address for yourself.

Log-in

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •