09-01-2009 04:47 AM - edited 03-18-2019 11:36 PM
My exchange server's ssl cert is a 5in1 UCC cert where the url of my mail server is one of the SANs and not the primay CN. Can CUPS deal with this? Is there a work around? The primary CN of this cert is used elsewhere so when i put in the url I want CUPS to use it complains and says SubjectCN mismatch and if try to correct it switches to the wrong url.
Thanks in advance!
09-01-2009 04:57 AM
It's not a CUPS-specific problem. CUPS just use standard SSL library to establish the connection.
Due to the specification of SSL, the requested destination has to match the certificate, either the subject name or the alternative name.
Maybe you can talk to your CA to put the Exchange into certificate as alternative name.
Again, this is product neutral. This is just the nature of the SSL.
Michael
09-01-2009 04:58 AM
Michael,
My exchange server URL is one of the alternate names on the cert.
Apologies if that wasn't clear.
Thanks!
09-01-2009 05:33 AM
On CUPS > Presence > Presence Gateway, did you use IP address or the FQDN of the Exchange? If the FQDN matches with the certificate's alternative name, it should work.
Michael
09-01-2009 05:36 AM
Michael,
I am using the FQDN, for the Exchange SSL Verification I get subject CN mismatch? Can I ignore that warning? Or is something else going?
Thanks!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide