Security - ssl certificate issue after renewal

Asked By ranjan kumar on 01-Nov-11 03:37 AM
after renew the ssl certificate we are facing issue of handshake below is the error detail.

request timeout (ret=30,err=SOAP 1.1 fault: SOAP-ENV:Client [no subcode]

"EOF was observed that violates the protocol. The client probably provided invalid authentication information."

Detail: SSL connect failed in tcp_connect()

Reena Jain replied to ranjan kumar on 01-Nov-11 03:47 AM
Hi,

Secure Sockets Layer (SSL) certificate security is a must for any ecommerce website. SSL benefits to you and your customers are vital. SSL Certificates are provided to the servers/websites by Certificate Authorities (CA). These certificates are provided only after due verification of the domain name, domain ownership, physical address, company incorporation certificate etc (depending on the terms of the CA). So, when a user is visiting a website through an Internet browser, there appears a lock symbol at the bottom of the browser if the website has a digital certificate. When that lock symbol is clicked, further information on the website/ certificate authority/ type of encryption etc are displayed. So, people can verify this information before doing any commercial transactions etc.

for more check these
http://www.excitingip.com/585/what-is-ssl-and-what-are-the-benefits-of-ssl-offloading/
http://www.bestsslcertificates.com/articles4.html

to solve the problem check this
https://kc.mcafee.com/corporate/index?page=content&id=KB66780

hope this will help you
Sri K replied to ranjan kumar on 01-Nov-11 04:20 AM

After your certificate renewal request is approved, download the certificate bundle and follow these instructions to install your renewed certificate.

  1. From the Start menu, click Run...
  2. Type mmc, and then click OK. The Microsoft Management Console (Console) window opens.
  3. In the Console window, click the File menu, and select Add/Remove Snap In. The Add or Remove Snap-ins window displays.
  4. Select Certificates, and then click Add.
  5. Select Computer Account, and then click Next.
  6. Select Local Computer, then click Finish.
  7. Click OK and close the Add or Remove Snap-ins window.
  8. In the Console window, click Certificates folder on the left.
  9. Right-click Intermediate Certification Authorities and mouse-over All Tasks, then click Import.
  10. In the Certificate Import Wizard, click Next.
  11. Click Browse to find the certificate file.
  12. Change the file extension filter in the bottom right corner to PKCS #7 Certificates (*.spc;*.p7b), select the*_iis_intermediates.p7b file, and then click Open.
  13. Click Next.
  14. Choose Place all certificates in the following store.
  15. Click Browse, select Intermediate Certification Authorities, and then click Next.
  16. Click Finish.
  17. Close the Console window.
  18. From the Start menu, go to Administrative Tools and click Internet Information Services.
  19. In the left panel, click the server name for the certificate you want to secure.
  20. Double-click Server Certificates.
  21. Right-click the certificate, and click Renew. The Renew an Existing Certificate wizard displays.
  22. Select Complete certificate renewal request.
  23. Click Next.
  24. Click Browse to locate your renewed certificate.
  25. Click Open
  26. Click Complete.
Jitendra Faye replied to ranjan kumar on 01-Nov-11 04:46 AM

To renew your SSL certificate for an IIS 7 Web server, generate a new certificate signing request (CSR) to submit when you request the renewal in your account. After your renewed certificate is issued, download it from your account and install it on your server. For more information, see Downloading an SSL Certificate.

You can also download the intermediate certificates from the repository.

To Generate a Renewal CSR

  1. From the Start menu, go to Administrative Tools and click Internet Information Services.
  2. In the left panel, click the server name for the certificate you want to renew.
  3. Double-click Server Certificates.
  4. Right-click the certificate, and click Renew. The Renew an Existing Certificate wizard displays.
  5. Select Create a renewal certificate request.
  6. Enter a location and file name for the CSR.
  7. Click Save.
  8. Open the generated CSR file, and copy all of the text.

Follow this link for complete post-
http://help.godaddy.com/article/4802
Hope this will help you.

ranjan kumar replied to Sri K on 01-Nov-11 05:14 AM
Hi All,

thanks for your reply.
this activity already i completed.

Below is the activity and issue details.
we extended the CA validity from regedit from validity unit 1 year to 3 year.
then we renewed the certificate bcouz before this CA was renewing certificate for 1 day only so we changed in CA by regedit.now its renewed for next 1 year.

then we installed it by mmc on our local coumputer A. and the same certificate and certificate chain on B server.
B server is sending some request to A to do process, but  80% request is successful and 20 % is failing, its occuring randomly.

please help!
ranjan kumar replied to Sri K on 01-Nov-11 05:14 AM
Hi All,

thanks for your reply.
this activity already i completed.

Below is the activity and issue details.
we extended the CA validity from regedit from validity unit 1 year to 3 year.
then we renewed the certificate bcouz before this CA was renewing certificate for 1 day only so we changed in CA by regedit.now its renewed for next 1 year.

then we installed it by mmc on our local coumputer A. and the same certificate and certificate chain on B server.
B server is sending some request to A to do process, but  80% request is successful and 20 % is failing, its occuring randomly.

please help!