SSL connection problems:

openfor

We try to exchage file with SEEBURGER EDIINT AS2 product.

We have problems to send file via SSL (HTTPS).
M-e-c as2 has problems to send the MDN and the other trasmissions because the partner requires a SSL connection.

1) We installed m-e-c as2 1.0 build 19 - build date: 21.09.07 14:31

2) We tested successfully the trasmission via SSL (HTTPS) between two m-e-c AS2 installation.

3) We obtain this error
[3:12:30 PM] m-e-c as2 1.0 build 19
[3:12:30 PM] (c) 2000-2007 mendelson-e-commerce GmbH Berlin, Germany
[3:12:31 PM] HSQL Database Engine 1.8.0 started.
[3:12:31 PM] Message queue server is started at localhost.
[3:12:34 PM] Message queue set up: #0.0.1037
[3:12:34 PM] Keys and certificates loaded from "/opt/mec-as2/certificates.p12".
[3:12:34 PM] Directory poll manager started.
[3:12:34 PM] Directory poll manager: Poll for partner "OSRAM" started. Ignore files: "--". Poll interval: 60s
[3:12:34 PM] Directory poll manager: Poll for partner "BOSCH" started. Ignore files: "--". Poll interval: 60s
[3:12:34 PM] Server startup in 4038 ms.
[3:21:45 PM] Keys and certificates loaded from "/opt/mec-as2/certificates.p12".
[3:28:34 PM] Processing the file "B81Ctest3.fromlse.filetest" for the receiver "BOSCH".
[3:28:34 PM] mec_as2-1195482514750-0@OPENFOR_AS2_BSH_AS2: Outgoing message signed with the algorithm SHA-1,using keystore alias "as2openfor".
[3:28:34 PM] mec_as2-1195482514750-0@OPENFOR_AS2_BSH_AS2: Outgoing message encrypted with the algorithm 3DES, using keystore alias "as2bosch".
[3:28:34 PM] mec_as2-1195482514750-0@OPENFOR_AS2_BSH_AS2: Outbound AS2 message created from "B81Ctest3.fromlse.filetest" for the receiver "BOSCH", raw message size: 2.00 KB
[3:28:34 PM] mec_as2-1195482514750-0@OPENFOR_AS2_BSH_AS2: The file "B81Ctest3.fromlse.filetest" has been deleted and enqueued into the processing message queue of the server.
[3:28:35 PM] mec_as2-1195482514750-0@OPENFOR_AS2_BSH_AS2: Sending message to https://portal.bsh-partner.com/devedi01/as2, sync MDN requested.

[3:28:35 PM] mec_as2-1195482514750-0@OPENFOR_AS2_BSH_AS2: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

[3:28:35 PM] mec_as2-1195482514750-0@OPENFOR_AS2_BSH_AS2: Transaction state written to /opt/mec-as2/messages/BOSCH/sent/B81Ctest3.fromlse.filetest_mec_as2-1195482514750-0@OPENFOR_AS2_BSH_AS2.sent.state.
[3:28:35 PM] mec_as2-1195482514750-0@OPENFOR_AS2_BSH_AS2: Connection problem, failed to transmit data.
[3:28:35 PM] mec_as2-1195482514750-0@OPENFOR_AS2_BSH_AS2: Message payload stored to "/opt/mec-as2/messages/BOSCH/error/AS2Message32091.as2".
[3:28:35 PM] mec_as2-1195482514750-0@OPENFOR_AS2_BSH_AS2: Raw outgoing message stored to "/opt/mec-as2/messages/BOSCH/error/raw/error32092.raw".

We can not undestand the problem..
and if the problems is on our site (m-e-c as2 problem) or remote site (SEEBURGER EDIINT AS2).

Have you some compatibility experience with SEEBURGER EDIINT AS2 ?
If yes, Have you checked the HTTPS (SSL connection) with it ?

Thanks in advance for your help

Erminio paoletti



heller
heller's picture
openfor, yes, I know about

openfor,

yes, I know about installations that communicate with Seeburger with HTTPS and without problems.

This seems to be a SSL keystore problem for the SSL connection, not a AS2 problem.

Could you please check the following things:

*Have you installed the root certificates of the CAs in the SSL keystore? The SSL keys and certificates are needed to be trusted
*Could you please check the path and the password to the SSL keystore in the m-e-c as2 configuration?

Regards
heller



openfor
PROBLEM SOLVED

OK we solved the questions.
The problem was that our partner give us only one certificate and we used it both for the sign/encrypt an for the SSL.

This morning we received the information that we had to use two differents certificates one for the sign/encrypt and one for the SSL.

So we change the SSL certificate in the SSL keystore and all the first tests work correctrly.

Sorry for the false problem
Thanks for you collaboration




© 1999-2007 mendelson-e-commerce GmbH. All right reserved.