Jump to content


Photo

Access Gateway connection error

Started by Andreas Küffner , 20 May 2011 - 09:23 AM
11 replies to this topic

Andreas Küffner Members

Andreas Küffner
  • 88 posts

Posted 20 May 2011 - 09:23 AM

Hi,

I'm trying to use access gateway to connect my corporate network but i get "SSL Error: Peer hostname mismatch" error. Any ideas?

info;

OS: mac os x 10.6.7
Access Gateway version: 2.0.1 (72)
CN in the SSL ceritificate is *.aksigorta.com.tr and my login url is acente.aksigorta.com.tr

note: i don't get any error at the windows 7/XP clients.

Edited by: Andreas Küffner on May 20, 2011 5:23 AM

Edited by: Andreas Küffner on May 20, 2011 5:25 AM



Reinhard Teischl Members

Reinhard Teischl
  • 1,845 posts

Posted 20 May 2011 - 11:17 AM

Hi Andreas,

which SSL certificate do you use? Private or public CA? Can you check if the root CA is missing on your Mac client?



Andreas Küffner Members

Andreas Küffner
  • 88 posts

Posted 20 May 2011 - 11:41 AM

Hi,

I'm attaching screenshot of certificate and error message. And i think root CA is present on my mac client.

Attached Files



Reinhard Teischl Members

Reinhard Teischl
  • 1,845 posts

Posted 20 May 2011 - 11:51 AM

I think that the certificate is signed by an intermediate certificate which is not trusted by default on Safari. Could you please check this?

http://www.globalsign.com/support/intermediate-root-install.php

Install the intermediate on your Mac and try again. Could you please check with Firefox too?



Andreas Küffner Members

Andreas Küffner
  • 88 posts

Posted 20 May 2011 - 12:10 PM

As your suggestion i tried with firefox and i got the same error (i attached firefox screenshots)

i couldn't find out which intermediate certificate i should install to mac client, all of links are given for servers, could you point me to the right certificate?

regards

Attached Files



Andreas Küffner Members

Andreas Küffner
  • 88 posts

Posted 21 May 2011 - 07:02 AM

Hi Reinhard,

I installed all the intermediate certificates to my mac client by using keychain but i get the same error message. And also i tried different versions of the CAG with no success.

regards.



Reinhard Teischl Members

Reinhard Teischl
  • 1,845 posts

Posted 21 May 2011 - 10:27 AM

Andreas,

do you see any certification issues on windows clients? Can you please verify this? Do you see the complete certificate path?



Andreas Küffner Members

Andreas Küffner
  • 88 posts

Posted 21 May 2011 - 12:21 PM

Hi Reinhard,

I don't get any certificate errors or warnings on CAG windows client and CAG connection log is clean. I'm attaching screenshot of certificate path on windows (also you can connect and see the certificate https://acente.aksigorta.com.tr)

regards

Attached Files



Reinhard Teischl Members

Reinhard Teischl
  • 1,845 posts

Posted 21 May 2011 - 08:35 PM

Quite strange,

http://www.digicert.com/help/ - you can check your site there, everything seems to be fine. I would check the Mac client again, can you verify if the globalsign root CA is in the local cert store?

https://www.racf.bnl.gov/docs/howto/grid/osxcertmgmt



Andreas Küffner Members
  • #10

Andreas Küffner
  • 88 posts

Posted 21 May 2011 - 10:18 PM

Hi Reinhard,

İ checked the certificate thru digicert website and certificate is verified (screenshot-1).

I'm attaching screenshot of my mac os x keychain, as you can see global sign root CA exists. (screenshot-2)

following threads also mention same error;

http://forums.citrix.com/thread.jspa?threadID=252808&tstart=0
http://forums.citrix.com/thread.jspa?threadID=251335&tstart=0

Attached Files



Andreas Küffner Members
  • #11

Andreas Küffner
  • 88 posts

Posted 25 May 2011 - 08:10 AM

Hi Reinhard,

did you check the mac client?

regards.



Reinhard Teischl Members
  • #12

Reinhard Teischl
  • 1,845 posts

Posted 25 May 2011 - 08:12 AM

Hi Andreas,

sorry for not replying to your thread. I've checked with some Mac clients and all are working fine, except that i'm not using a wildcard certificate. I would suggest to open up a Citrix support case on this.