Forum Discussion
Chris_G_Davis_1
Nimbostratus
Dec 12, 2008Oracle 10g SSL Offload - JInitiator:X509CertChainInvalidErr error
Hi,
We are in the process of implementing ssl offload on our LTM-3400’s for Oracle 10g. The servers we are load balancing to on the backend are listening on port 80. We have a valid Verisign cert in place. The first time you connect to the ssl vip the server downloads “JInitiator” to the local computer which is a java program. Once the installation is complete it attempts to load the app from the server. But it fails with an “X509CertChainInvalidErr” java error. I figured out a work around for individual computers, but this isn’t a valid solution for the general public. The work around is to add the cert assigned to the ssl vip to what a I think is a cert chain file call “C:\Program Files\Oracle\JInitiator 1.3.1.26\lib\security\certdb.txt on the local computer. Once added I restart the browser and all is well.
Like I said earlier this isn’t a practical work around as this site will be used by the public.
Has anyone seem this or know how to fix it?
I attached a copy of the certdb.txt (example-certdb.txt) file without my cert for an example.
Any help would be greatly appreciated.
Thanks,
Christopher G Davis
Sr. Network Engineer
SITA Atlanta Data Center
- hoolio
Cirrostratus
Hi Chris, - Jacquiec_105785
Nimbostratus
Hi Chris - hoolio
Cirrostratus
Hi Jacquie, - Jacquiec_105785
Nimbostratus
No I have a certificate & key for the website configured in the client SSL profile. Do I need to convert this into a certificate bundle? I wasn't sure how to do that. - hoolio
Cirrostratus
You can check SOL6401 (linked above) for details on configuring an intermediate cert: - Jacquiec_105785
Nimbostratus
Tried adding the ca-bundle from the chain drop down as well as having the website certificate and key configured but still getting the same error. - hoolio
Cirrostratus
Sorry, I was suggesting that you download the most current intermediate certificate from the certificate authority, add that to the bundle and then update the client SSL profile by clicking save. The last step loads the changed cert file into LTM memory for use. If you get stuck in this process, you could open a case with F5 Support and ask for help. - Yuliy_100882
Nimbostratus
I am trying to implement the SSL for Oracle 10g Forms/Reports standalone behind the BIG-IP 9.3.1 Build 37.1. - Chris_Akker_129Historic F5 AccountHi Yuliy, take a look at the F5 deployment guide for Oracle 10g. It has a section on SSL offload, here: http://www.f5.com/pdf/deployment-guides/f5-oracle10g-dg.pdf
- jrcma_oracle_47
Nimbostratus
hi chris,
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects