<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Support problem in Server Management - Systems Insight Manager</title>
    <link>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981851#M26845</link>
    <description>Ok.&lt;BR /&gt;&lt;BR /&gt;I HAVE A FIX!!!&lt;BR /&gt;&lt;BR /&gt;This problem will occur when you give SIM any certificate that is not self-signed.  This includes VeriSign-signed certificates as well as company CA-signed (e.g. Windows Certificate Authority) certificates.&lt;BR /&gt;&lt;BR /&gt;These actions need to be carried out on the HP SIM server.&lt;BR /&gt;&lt;BR /&gt;1. Export the CA certificate in base-64 format and save the file and take note of the path (e.g. c:\myca.cer).&lt;BR /&gt;&lt;BR /&gt;2. Open the C:\hp\hpsmh\data\htdocs\isee\unified-collector\xml\uc-configuration.xml and locate the line that begins with &lt;ENTRY key="SMHCACERTFILE" .=""&gt;&lt;/ENTRY&gt;&lt;BR /&gt;Example:&lt;BR /&gt;&lt;ENTRY key="SMHCACERTFILE" value="C:/hp/sslshare/cert.pem"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;&lt;BR /&gt;3. Move your myca.cer file to the directory specified in the value on this line (e.g. c:\hp\sslshare).&lt;BR /&gt;&lt;BR /&gt;Now, the full path to your myca.cer file should be c:\hp\sslshare\myca.cer&lt;BR /&gt;&lt;BR /&gt;NOTE: In the XML file, you should use the forward-slash (/).  Windows normally specifies path names with a backslash (\).&lt;BR /&gt;&lt;BR /&gt;4. Update the "value" value on the &lt;ENTRY key="SMHCACERTFILE" line="" in="" the="" uc-configuration.xml="" file="" to="" point="" to="" the="" new="" path="" and="" file="" name="" for="" your="" myca.cer="" file.=""&gt;&lt;/ENTRY&gt;&lt;BR /&gt;Syntax:&lt;BR /&gt;&lt;ENTRY key="SMHCACERTFILE" value="C:/hp/sslshare/[CA cert file]"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;&lt;BR /&gt;Example:&lt;BR /&gt;&lt;ENTRY key="SMHCACERTFILE" value="C:/hp/sslshare/myca.cer"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;&lt;BR /&gt;5. Open the C:\hp\hpsmh\data\htdocs\isee\xml\isee-gui-configuration.xml and locate the line that begins with &lt;ENTRY key="SMHCACERTFILE" .=""&gt;&lt;/ENTRY&gt;&lt;BR /&gt;Example:&lt;BR /&gt;&lt;ENTRY key="SMHCACERTFILE" value="C:/hp/sslshare/cert.pem"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;&lt;BR /&gt;6. Update the "value" value on the &lt;ENTRY key="SMHCACERTFILE" line="" in="" the="" uc-configuration.xml="" file="" to="" point="" to="" the="" new="" path="" and="" file="" name="" for="" your="" myca.cer="" file.=""&gt;&lt;/ENTRY&gt;&lt;BR /&gt;Syntax:&lt;BR /&gt;&lt;ENTRY key="SMHCACERTFILE" value="C:/hp/sslshare/[CA cert file]"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;&lt;BR /&gt;Example:&lt;BR /&gt;&lt;ENTRY key="SMHCACERTFILE" value="C:/hp/sslshare/myca.cer"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;&lt;BR /&gt;------------------&lt;BR /&gt;DONE!&lt;BR /&gt;&lt;BR /&gt;The isee-gui-configuration.xml file fixes the problem on the Entitlement tab.&lt;BR /&gt;The uc-configuration.xml file fixes the problem with all the other tabs.</description>
    <pubDate>Fri, 25 Apr 2008 00:03:28 GMT</pubDate>
    <dc:creator>John Hossbach</dc:creator>
    <dc:date>2008-04-25T00:03:28Z</dc:date>
    <item>
      <title>Remote Support problem</title>
      <link>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981843#M26837</link>
      <description>Installation works OK. Remote Support settings also work and I am able to update my data to isee. But when I open the "Remote Support Services" tab in Remote Support Configuration and Services I get the following :&lt;BR /&gt;&lt;BR /&gt;HTTP Error: cURL ERROR: 60: SSL certificate problem, verify that the CA cert is OK. Details:&lt;BR /&gt;error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failedurl: &lt;A href="https://127.0.0.1:50002/mxsoap/services/MxpiMain5_1http_code:" target="_blank"&gt;https://127.0.0.1:50002/mxsoap/services/MxpiMain5_1http_code:&lt;/A&gt; 0header_size: 0request_size: 0filetime: -1ssl_verify_result: 0redirect_count: 0total_time: 0namelookup_time: 0connect_time: 0pretransfer_time: 0size_upload: 0size_download: 0speed_download: 0speed_upload: 0download_content_length: 0upload_content_length: 0starttransfer_time: 0redirect_time: 0</description>
      <pubDate>Mon, 16 Apr 2007 02:55:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981843#M26837</guid>
      <dc:creator>Bart Korsten</dc:creator>
      <dc:date>2007-04-16T02:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Support problem</title>
      <link>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981844#M26838</link>
      <description>I'm afraid I don't have a solution for this one, but I'm experiencing a similar issue. When i go into "Remote Support Services", I get the following message:&lt;BR /&gt;&lt;BR /&gt;"HTTP Error: CURL Extension, or OpenSSL extension w/ PHP version &amp;gt;= 4.3 is required for HTTPS"&lt;BR /&gt;&lt;BR /&gt;No servers are shown in the list either, and no entitlement icons like before.&lt;BR /&gt;&lt;BR /&gt;I've tried this on IE on several different versions and also directly on the server, same issue. Anyone have a solution for this one?</description>
      <pubDate>Fri, 20 Apr 2007 05:53:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981844#M26838</guid>
      <dc:creator>U. Rasmussen</dc:creator>
      <dc:date>2007-04-20T05:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Support problem</title>
      <link>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981845#M26839</link>
      <description>Anybode who has a solution for this problem ? Do have the exact same error.&lt;BR /&gt;Already switched over from a proxy-connection to a direct connection to HP.&lt;BR /&gt;&lt;BR /&gt;Bart, do you use your own certificates in HPSIM ?</description>
      <pubDate>Wed, 02 May 2007 08:44:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981845#M26839</guid>
      <dc:creator>Martin Kers</dc:creator>
      <dc:date>2007-05-02T08:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Support problem</title>
      <link>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981846#M26840</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I do not use my own cert's because this results in a nonfunctional VMM service. But that's an other problem :) The weird thing is that if I use the command "Contract and warranty Data Collection" on the option menu, the machines get identified correctly and support contracts are found at HP.</description>
      <pubDate>Wed, 02 May 2007 08:58:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981846#M26840</guid>
      <dc:creator>Bart Korsten</dc:creator>
      <dc:date>2007-05-02T08:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Support problem</title>
      <link>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981847#M26841</link>
      <description>I too have the exact same error.  I have logged a job with HP and they are trying to help me out.  Just wondering if any of you guys worked out what the problem was?  Or did you go for the rebuild.  If HP figure out what is going on I will post it here.  Cheers.</description>
      <pubDate>Tue, 16 Oct 2007 21:02:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981847#M26841</guid>
      <dc:creator>L Davis</dc:creator>
      <dc:date>2007-10-16T21:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Support problem</title>
      <link>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981848#M26842</link>
      <description>Any news on this thread?  I am experiencing this problem and I *did* install our own certificate.</description>
      <pubDate>Tue, 18 Dec 2007 17:43:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981848#M26842</guid>
      <dc:creator>Clancy</dc:creator>
      <dc:date>2007-12-18T17:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Support problem</title>
      <link>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981849#M26843</link>
      <description>&lt;!--!*#--&gt;As you may or may not know, this error is generated by the System Management Home page when there is a Cert failure or mismatch.  You can get around this error by opt'ing to not check the cert.  To do this perform the following steps:&lt;BR /&gt;&lt;BR /&gt;On the CMS:&lt;BR /&gt;1. Locate the file isee-soap-calls.php in the c:\hp\hpsmh\data\htdocs\isee\ directory.&lt;BR /&gt;&lt;BR /&gt;2. Make a copy of this file as a backup.&lt;BR /&gt;&lt;BR /&gt;3. Using Notepad, open the &lt;BR /&gt;isee-soap-calls.php file and locate the following line:&lt;BR /&gt;&lt;BR /&gt;  $cert['verifyhost'] = 0;&lt;BR /&gt;&lt;BR /&gt;4.  Insert the following line after the line lcoated in step 3:&lt;BR /&gt;&lt;BR /&gt;  $cert['verifypeer'] = 0;&lt;BR /&gt;&lt;BR /&gt;The updated file should now contain:&lt;BR /&gt;&lt;BR /&gt;  $cert['verifyhost'] = 0;&lt;BR /&gt;  $cert['verifypeer'] = 0;&lt;BR /&gt;&lt;BR /&gt;5.  Save the file and either refresh the page in SIM or logout and back in again.&lt;BR /&gt;&lt;BR /&gt;6.  If this fails to resolve the problem or casues additional problems, restore the original file.</description>
      <pubDate>Mon, 17 Mar 2008 12:26:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981849#M26843</guid>
      <dc:creator>IRS4Ever</dc:creator>
      <dc:date>2008-03-17T12:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Support problem</title>
      <link>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981850#M26844</link>
      <description>Has anyone been able to actually fix this problem yet?</description>
      <pubDate>Sat, 05 Apr 2008 15:20:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981850#M26844</guid>
      <dc:creator>John Hossbach</dc:creator>
      <dc:date>2008-04-05T15:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Support problem</title>
      <link>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981851#M26845</link>
      <description>Ok.&lt;BR /&gt;&lt;BR /&gt;I HAVE A FIX!!!&lt;BR /&gt;&lt;BR /&gt;This problem will occur when you give SIM any certificate that is not self-signed.  This includes VeriSign-signed certificates as well as company CA-signed (e.g. Windows Certificate Authority) certificates.&lt;BR /&gt;&lt;BR /&gt;These actions need to be carried out on the HP SIM server.&lt;BR /&gt;&lt;BR /&gt;1. Export the CA certificate in base-64 format and save the file and take note of the path (e.g. c:\myca.cer).&lt;BR /&gt;&lt;BR /&gt;2. Open the C:\hp\hpsmh\data\htdocs\isee\unified-collector\xml\uc-configuration.xml and locate the line that begins with &lt;ENTRY key="SMHCACERTFILE" .=""&gt;&lt;/ENTRY&gt;&lt;BR /&gt;Example:&lt;BR /&gt;&lt;ENTRY key="SMHCACERTFILE" value="C:/hp/sslshare/cert.pem"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;&lt;BR /&gt;3. Move your myca.cer file to the directory specified in the value on this line (e.g. c:\hp\sslshare).&lt;BR /&gt;&lt;BR /&gt;Now, the full path to your myca.cer file should be c:\hp\sslshare\myca.cer&lt;BR /&gt;&lt;BR /&gt;NOTE: In the XML file, you should use the forward-slash (/).  Windows normally specifies path names with a backslash (\).&lt;BR /&gt;&lt;BR /&gt;4. Update the "value" value on the &lt;ENTRY key="SMHCACERTFILE" line="" in="" the="" uc-configuration.xml="" file="" to="" point="" to="" the="" new="" path="" and="" file="" name="" for="" your="" myca.cer="" file.=""&gt;&lt;/ENTRY&gt;&lt;BR /&gt;Syntax:&lt;BR /&gt;&lt;ENTRY key="SMHCACERTFILE" value="C:/hp/sslshare/[CA cert file]"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;&lt;BR /&gt;Example:&lt;BR /&gt;&lt;ENTRY key="SMHCACERTFILE" value="C:/hp/sslshare/myca.cer"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;&lt;BR /&gt;5. Open the C:\hp\hpsmh\data\htdocs\isee\xml\isee-gui-configuration.xml and locate the line that begins with &lt;ENTRY key="SMHCACERTFILE" .=""&gt;&lt;/ENTRY&gt;&lt;BR /&gt;Example:&lt;BR /&gt;&lt;ENTRY key="SMHCACERTFILE" value="C:/hp/sslshare/cert.pem"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;&lt;BR /&gt;6. Update the "value" value on the &lt;ENTRY key="SMHCACERTFILE" line="" in="" the="" uc-configuration.xml="" file="" to="" point="" to="" the="" new="" path="" and="" file="" name="" for="" your="" myca.cer="" file.=""&gt;&lt;/ENTRY&gt;&lt;BR /&gt;Syntax:&lt;BR /&gt;&lt;ENTRY key="SMHCACERTFILE" value="C:/hp/sslshare/[CA cert file]"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;&lt;BR /&gt;Example:&lt;BR /&gt;&lt;ENTRY key="SMHCACERTFILE" value="C:/hp/sslshare/myca.cer"&gt;&lt;/ENTRY&gt;&lt;BR /&gt;&lt;BR /&gt;------------------&lt;BR /&gt;DONE!&lt;BR /&gt;&lt;BR /&gt;The isee-gui-configuration.xml file fixes the problem on the Entitlement tab.&lt;BR /&gt;The uc-configuration.xml file fixes the problem with all the other tabs.</description>
      <pubDate>Fri, 25 Apr 2008 00:03:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981851#M26845</guid>
      <dc:creator>John Hossbach</dc:creator>
      <dc:date>2008-04-25T00:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Support problem</title>
      <link>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981852#M26846</link>
      <description>Has anyone managed to resolve this issue yet using either of the fixes above?</description>
      <pubDate>Thu, 05 Jun 2008 09:27:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981852#M26846</guid>
      <dc:creator>John Lernihan</dc:creator>
      <dc:date>2008-06-05T09:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Support problem</title>
      <link>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981853#M26847</link>
      <description>John,&lt;BR /&gt;&lt;BR /&gt;The problem with SIM is that although it allows you to use your own certificate, it assumes whatever certificate you provide is self-signed.  Of course, what's the point in using your own certifcate if the it is self-signed aside from simply having your name on it -- no one trusts it unless you install it on all your clients.&lt;BR /&gt;&lt;BR /&gt;The 'verifypeer' "fix" (the first one listed) is actually not a fix at all.  Setting verifypeer to 0 simply tells SIM not to validate the certificate against trusted sources (or untrusted sources).  You'll never know if the certificate is bad or good.  If you do go this route, make sure you also edit the uc-soap-calls.php file in C:\hp\hpsmh\data\htdocs\isee\unified-collector to "fix" the other tabs.  However, for security, I don't recommend disabling the security checking on certificates as this is the point to certificates in the first place.&lt;BR /&gt;&lt;BR /&gt;The second fix (the one I posted) corrects SIM's assumption of self-signed certificates.  There are two entries in the XXX-configuration.xml file to take note of: SMHCERTFILE and SMHCACERTFILE.  SMHCERTFILE (should not be changed) points to the certificate file you uploaded to SIM.  SMHCACERTFILE points to the same file.  This is the problem.  When SIM tries to validate the CERTFILE, it uses the CACERTFILE.  For self-signed certificates, these should be the same.  For CA-signed certificates, the CACERTFILE needs to point to the CA's certificate.  SIM currently provides no interface for updating this value, so you must edit it yourself when you upload a new certificate that uses a different signer (self or CA).&lt;BR /&gt;&lt;BR /&gt;As far as the two different directories, that's just the way they designed the remote support pack.  The entitlement tab is separate from all the other tabs.  No clue why. :-)</description>
      <pubDate>Thu, 05 Jun 2008 11:11:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981853#M26847</guid>
      <dc:creator>John Hossbach</dc:creator>
      <dc:date>2008-06-05T11:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Support problem</title>
      <link>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981854#M26848</link>
      <description>Hi John&lt;BR /&gt;&lt;BR /&gt;   I tried your response, the first and the second but no working for me. Anybody has a solution to this problem??&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;CF</description>
      <pubDate>Tue, 08 Jul 2008 20:43:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981854#M26848</guid>
      <dc:creator>Juan de Los Palotes</dc:creator>
      <dc:date>2008-07-08T20:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Support problem</title>
      <link>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981855#M26849</link>
      <description>Are you using your own certificate?  If you switch back to the HP SIM certificate does it work fine?</description>
      <pubDate>Tue, 08 Jul 2008 20:58:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981855#M26849</guid>
      <dc:creator>John Hossbach</dc:creator>
      <dc:date>2008-07-08T20:58:46Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Support problem</title>
      <link>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981856#M26850</link>
      <description>Hi John&lt;BR /&gt;&lt;BR /&gt;  Really I don't known wich certificate copy, I found this certificate and use this to make your troubleshooting. This is the certificate C:\Program Files\HP\Systems Insight Manager\config\certstor\hpsimwbem.cert. This not work to me, then I use the backup. Which certificate do you use it?. Thanks a lot for your response.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;CF</description>
      <pubDate>Wed, 09 Jul 2008 00:40:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981856#M26850</guid>
      <dc:creator>Juan de Los Palotes</dc:creator>
      <dc:date>2008-07-09T00:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Support problem</title>
      <link>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981857#M26851</link>
      <description>Fix in this thread was for another SSL error..&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums13.itrc.hp.com/service/forums/questionanswer.do?threadId=1367073" target="_blank"&gt;http://forums13.itrc.hp.com/service/forums/questionanswer.do?threadId=1367073&lt;/A&gt;</description>
      <pubDate>Thu, 27 Aug 2009 16:46:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/server-management-systems/remote-support-problem/m-p/3981857#M26851</guid>
      <dc:creator>SmooshedFace76</dc:creator>
      <dc:date>2009-08-27T16:46:18Z</dc:date>
    </item>
  </channel>
</rss>

