James Chavez wrote: > Hello, > I have 2 servers running FDS. > I have setup My directory servers to use SSL for the directory server > and Admin server. For my problem server I generated both the directory > server cert and admin server cert on the directory server acting as the > CA. I exported the Server-Cert2, server-cert2 in .p12 format and I > imported them as well as the CA cert into both the admin server and > directory server. I am able to establish SSL client sessions to the > directory server but I cannot login to the admin server through the > GUI. > I was able to login fine before enabling SSL...Unlike on this server, > the server acting as the root CA everything works fine. > > I get the following error at the GUI login screen. > authenticating User ID "cn=Directory Manager" > java.io.InterruptedIOException: HTTP response timeout > > In the error log I have this. The directory server that I can log into I > get the same messages but not the segmentation fault. > > > [notice] caught SIGTERM, shutting down > [notice] Access Host filter is: *.fedora > [notice] Access Address filter is: * > [notice] Access Host filter is: *.fedora > [notice] Access Address filter is: * > [error] SSL_InheritMPServerSIDCache failed > [error] SSL Library Error: -8191 Library Failure > [notice] Apache/2.2.8 (Unix) configured -- resuming normal operations > [notice] child pid 3284 exit signal Segmentation fault (11) > What platform? What version of fedora-ds-admin? rpm -qi fedora-ds-admin > Here are my Cert data bases > > [root at scooby ~]# certutil -L -d /etc/dirsrv/admin-serv/ > > Certificate Nickname Trust > Attributes > > SSL,S/MIME,JAR/XPI > > CA certificate CT,, > server-cert2 u,u,u > [root at scooby ~]# certutil -L -d /etc/dirsrv/slapd-scooby/ > > Certificate Nickname Trust > Attributes > > SSL,S/MIME,JAR/XPI > > CA certificate CT,, > Server-Cert2 u,u,u > > > > > > > Any ideas. > > Thanks > James > > CONFIDENTIALITY > This e-mail message and any attachments thereto, is intended only for use by the addressee(s) named herein and may contain legally privileged and/or confidential information. If you are not the intended recipient of this e-mail message, you are hereby notified that any dissemination, distribution or copying of this e-mail message, and any attachments thereto, is strictly prohibited. If you have received this e-mail message in error, please immediately notify the sender and permanently delete the original and any copies of this email and any prints thereof. > ABSENT AN EXPRESS STATEMENT TO THE CONTRARY HEREINABOVE, THIS E-MAIL IS NOT INTENDED AS A SUBSTITUTE FOR A WRITING. Notwithstanding the Uniform Electronic Transactions Act or the applicability of any other law of similar substance and effect, absent an express statement to the contrary hereinabove, this e-mail message its contents, and any attachments hereto are not intended to represent an offer or acceptance to enter into a contract and are not otherwise intended to bind the sender, Sanmina-SCI Corporation (or any of its subsidiaries), or any other person or entity. > > -- > Fedora-directory-users mailing list > Fedora-directory-users at redhat.com > https://www.redhat.com/mailman/listinfo/fedora-directory-users > -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3258 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.fedoraproject.org/pipermail/389-users/attachments/20081209/d75ade9b/attachment.bin