cancel
Showing results for 
Search instead for 
Did you mean: 

EV 10.0.4 and check for server certificate revocation

keebon
Level 2
Partner

Hi

First time post. Hoping I can get some help/answers. Senario is below:

Users and Computers are in Domain A, private

Enterprise Vault Servers are in Domain B. private

One way trust exist between Domain A and Domain B, Domain A, trust Domain B.

EV servers are accessible via https and have an internal CA for domain B

When we go to an archived item, users is get the error

error.png

A dtrace from the client logs show:

 

09/06/2014 21:07:39.772[12312][M]: HaveConnection::ExecuteTest - Connection test to: <server> /EnterpriseVault/clienttest.gif failed
09/06/2014 21:07:39.773[12312][M]: HaveConnection::ExecuteTest (38157314) - Ending connection
09/06/2014 21:07:39.773[12312][L]: ~HaveConnection::ExecuteTest
09/06/2014 21:07:39.773[12312][M]: Could not contact the EV web server (https://<server>/EnterpriseVault)
09/06/2014 21:07:39.773[12312][L]: ~DesktopCommon::GetWebAppURLEx: 0x0

When I turn off the setting in IE for "check for server certificate revocation," we can retrieve the item and view it.

Now for my issue, the customer wants to keep "check for server certificate revocation" setting turned on, is there a configuration that would allow this setting? All research points to a cert, but since these servers are in a private space, a public cert will not work.

 

Ideas?

 

Thank in advance

-kevin

 

 

 

 

 

 

4 REPLIES 4

Rob_Wilcox1
Level 6
Partner

What happens if the client goes in IE to https://evserver/enterprisevault/search.asp? What sort of prompting about certificates is given?

Working for cloudficient.com

keebon
Level 2
Partner

 

 

No prompt for a certificate

 

error2.png

keebon
Level 2
Partner

Also on search, no prompt of certificate:

 

error3.png

shailesh866
Level 4
Employee Accredited

Its definately related to CERT. Could you check http://www.symantec.com/docs/TECH55042.

Also, please note in IE "Check for server certificate revocation" and "Check for publisher's certification revocation" can be turn off if you are using SSL for http communication. The data will still be encrypted even if we turn off these settings. 
http://technet.microsoft.com/en-us/library/bb457027.aspx 
http://blogs.msdn.com/b/alimaz/archive/2008/10/16/check-for-publisher-s-certificate-revocation-slowi...