Jump to content


Photo

ssl error 5 an unclassified error occurred error code 0x80090308

Started by Kalif Davis , 23 July 2007 - 03:52 PM
8 replies to this topic

Kalif Davis Members

Kalif Davis
  • 62 posts

Posted 23 July 2007 - 03:52 PM

This error occurs after I log in through the web interface and click on an application. Checked to make sure the STA was running and it is. Removed and re-installed certificates on WI, PS 4.5 server and client workstation. I have also tried three different version of the web agent. (9,9.23,10.1)For some reason I think it has something to do with my certificates but I don't see it. Any ideas



James Hong Members

James Hong
  • 170 posts

Posted 24 July 2007 - 01:02 AM

well without seeing your config, i cant say much but
1 does user sees valid cert when web page is opened? (if using IE, pad lock on buttom right hand side)
if not, root cert or server cert may not be valid

2 can you SAVE the ICA file ? (right click the app and choose save as on client's IE)
if you cant save it, may be you should check STA config.
have you changed XML port ? then STA port should be changed too (eg http://server:8080/stablahblah)



Kalif Davis Members

Kalif Davis
  • 62 posts

Posted 24 July 2007 - 01:29 PM

I do see the cert padlock next to the address bar after logging in and it does say it's a valid cert. I can right click the app and save it to my desktop as a ICA file. But when I double click on the file on my desktop i still get the same error. Anything that you need me to send that would help I can do.



Kalif Davis Members

Kalif Davis
  • 62 posts

Posted 24 July 2007 - 01:40 PM

Forgot to mention. We did change the xml port to 8080. I went in IIS on the presentation server and checked the STA port is also set at 8080.



James Hong Members

James Hong
  • 170 posts

Posted 24 July 2007 - 11:30 PM

goto wi config and make sure sta is set to
http://servername:8080/scripts/ctxsta.dll

so is CSG config



Kalif Davis Members

Kalif Davis
  • 62 posts

Posted 26 July 2007 - 02:27 PM

checked and that's done do you know anything else I can look at



James Hong Members

James Hong
  • 170 posts

Posted 26 July 2007 - 11:46 PM

1 is there any proxy/SSL accerelator between the user-CSG ?
Can you enable log/filter on the proxy and see if its interfering with SSL ? 0x80090308 is handshake error, something may be trying to re-do SSL(reverse proxy)

2 if you have registered multiple XML/STA broker, can you make it only 1 see if that makes any difference.
if it is working with one, then it may be CSG/WI is unable to contact XML

3 can you post what you get when you use IE from WI server to URL of STA(http://servername:8080/scripts/ctxsta.dll) as well as CSG server.

is it HTTP 404 ? HTTP 400 ? You must get HTTP 400
If you get HTTP404, then CSG/WI is unable to contact that XML/STA.



Kalif Davis Members

Kalif Davis
  • 62 posts

Posted 27 July 2007 - 01:59 PM

We are not using a proxy/SSL accelerator or proxy at all. We only have one xml/sta broker as far as I know. Where would I look to see if that's been changed? when I go to the http://servername:8080/scripts/ctxsta.dll the page displays HTTP:405 Method not allowed



Brian Murphy Members

Brian Murphy
  • 105 posts

Posted 27 July 2007 - 08:43 PM

Is this an internal / external / both arrangement?

What is the connection setting under:
"Manage Secure Client Access" > "Edit DMZ Setting"
[Direct, Gateway Direct??]

If set to something other than Direct what is the setting under: "Manage Secure Client Access" > "Edit Gateway Settings"