Profile picture for user pamillet

Hello

We have installed a new certificat on the ARIS server, following ACC documentation

all is ok for https access

but we have an error when starting a .jar client..

message "impossible to connect to server, you try to use a SSL connection, the certificat is not approved or not imported in JRE..."

not found in documentation something regarding certificat and .jar...

thanks for your help

 

pam

 

 

by Martin Schröder
Badge for 'Contributor' achievement
Posted on Tue, 10/23/2018 - 13:39

Hello Pierre,

the message suggest two possible reasons "...the certificate is not approved or not imported in JRE...".

So either the certificate cannot be validated against the issuer (do you use a self-signed cert. or was it issued by a public Certificate Authority?) or it may not be present in the Java keystore.

The ACC Command Line doc points out: "If your company uses own CA get a certificate from this CA and add this CA to the trust store of all clients."

Both the Download Client Configuration Guide and Basic Trouble Shooting Guide offer more details than the ACC docu.

Regards, Martin

0
by Frank Weyand
Posted on Wed, 10/24/2018 - 07:52

Hi folks,

let me inform you that the new, recently released version of ARIS 10 (SR 6) is able to handle this for you.

Before 10.0 SR 6:

Normally, if you use a self-signed certificate) you create a file "cacerts" and place it in this folder...

<server install dir>\server\bin\work\work_abs_<s|m|l>\base\webapps\abs\downloadClient\config

... on all ABS nodes.

All download clients (unfortunately not installed clients) will automatically use this cacerts file.

You create this file via importing this into an JRE with the "keytool" and copy this file to the location specified above.

Since 10.0 SR 6:

ARIS Architect/Designer, installed or download, is able to import this file in the used JRE. The user is prompted whether he wants to accept this certificate in order to connect to the server. Cool, isn't it?

BTW: an admin can use this mechanism to let the "cacerts" file be created from ARIS and then use it to copy it on the location on the server, so other users are not prompted at all.

Bye,

Frank

0
by Pierre-Alain MILLET Author
Posted on Wed, 10/24/2018 - 09:36

good news !

but seems not available in download area for university ?

pam

0
by Frank Weyand
Posted on Thu, 10/25/2018 - 11:09

Hi,

no, sorry, currently, the 10.0 SR 5 version is available for university users...

Bye,

Frank

0
by Pierre-Alain MILLET Author
Posted on Tue, 11/06/2018 - 12:05

if that can help...

pb solved with a java security expert,

the error was coming from the "certification chain" in the .crt...not correctly set...

all is now ok

0

Featured achievement

Genius
You like to help others solve their problems by answering questions.
Recent Unlocks
  • KF
  • KH
  • RG
  • Profile picture for user Vee_ARIS
  • Profile picture for user smarty
  • PacMan

Leaderboard

|
icon-arrow-down icon-arrow-cerulean-left icon-arrow-cerulean-right icon-arrow-down icon-arrow-left icon-arrow-right icon-arrow icon-back icon-close icon-comments icon-correct-answer icon-tick icon-download icon-facebook icon-flag icon-google-plus icon-hamburger icon-in icon-info icon-instagram icon-login-true icon-login icon-mail-notification icon-mail icon-mortarboard icon-newsletter icon-notification icon-pinterest icon-plus icon-rss icon-search icon-share icon-shield icon-snapchat icon-star icon-tutorials icon-twitter icon-universities icon-videos icon-views icon-whatsapp icon-xing icon-youtube icon-jobs icon-heart icon-heart2 aris-express bpm-glossary help-intro help-design Process_Mining_Icon help-publishing help-administration help-dashboarding help-archive help-risk icon-knowledge icon-question icon-events icon-message icon-more icon-pencil forum-icon icon-lock