cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
813
Views
0
Helpful
4
Replies

Zone failed between expressway C and E

romy kurniawan
Level 1
Level 1

I'm currently deploying expressway for MRA. I'm having trouble with the zone I created between expressway C and E, the status failed.

I have uploaded server certificate for both servers and uploaded CA on Trusted CA.

Expressway C Zone status

romykurniawan_0-1662624018455.png

Expressway C Secure Traversal Test

romykurniawan_1-1662624079777.png

Expressway C Trustes CA Certificate

romykurniawan_2-1662624207700.png

Expressway E Zone Status

romykurniawan_3-1662624260508.png

Expressway E Trusted CA Certificate

romykurniawan_4-1662624346152.png

 

4 Replies 4

b.winter
VIP
VIP

Are the Root-CA's, which signed the EXP-C cert in the trust of EXP-E?
Are the Root-CA's, which signed the EXP-E cert in the trust of EXP-C?
Is the FQDN of the zone included in the EXP-E cert?

You can also check the logs for more info.

From the error its because of the Certificate which you uploaded.

Can you explain more on  how you signed the certificates and which server/CA certificates you uploaded on each servers.



Response Signature


The certificates that says Not a CA should not be in the trusted CA trust store, please remove them. This is not directly related to your issue, but newer the less it is not accurate or needed to be there. What you do need to have is the certificate(s) of the CA(s) that’s signed each of the C and E certificates uploaded on both the C and E in the trusted CA trust store. This is so that the E can verify the validity of the C and the reverse.



Response Signature


On the Traversal test you have not filled in the name of the C that you want to verify. See the below screenshot for reference.

image.png

Apart from this can you please share screenshots of the entire traversal zone configuration from both C and E?



Response Signature