HOME   OA   JOBS at KOAL   SITEMAP   中文版  
KOAL ABOUT US PRESS CENTER PRODUCTS SUPPORT CONTACT US
 
 
SSL
 
SVS
 
Network Shield Desktop Security Sets
 
Download
 
Hotline:021-62327008
 
      SSL FAQs

Q:

What are the universal steps of debugging SSL?

 

A:

1.Looking over the catalog of the SSL authentication service;
2.Checking whether the connectiong between user terminal and SSL gateway network is available
3.Please use serveal user terminals to verdict the problems hereof and find out where errors are —— in user terminal or in server terminal.

Q:

How to solve such problem after using SSL gateway,that is, some browsers are accessible while some are not?

 

A:

1."Unable to display the current page" is shown instead of the personal certificate select box in the process of accessing HTTP through IE. The is mainly because the communication between user terminal and SSL gateway network is not accessible.. If the network is smooth, please confirm the problems through the catalog of SSL gateway. If the problems are stilled could not be confirmed, please refer to "2.4: What to do under the circumstances of failing to establish the security conection with SSL gateway and failing to get reasons for the problems through service catalog "

2.The personal certificate select box is shown in the process of accessing HTTP through IE. But "Unable to display the current page" is shown after submitting the personal certificate. This error can be verdicted through the catalog of SSL gateway. This is usually because the invalid (not admitted by SSL gateway) personal certificate is submitted: the certificate is not issued by the CA recognized by SSL gateway、"digital sign" key is not available、something is wrong in the equipment for the personal certificate storage.

3.Such error still appears in case of the legal personal certificate. Because the current browsers do not have 128-bit encryotion strenth, this problem is probably caused by the compulsory 128-bit encryption made by SSL gateway. One of the solutions to it is to change the setting of "encryption strenth" in the parameter settings of SSl service from "High" to "All" (pic.9); the second way is to upgrade the browser, (user may download IE 128-bit encryption packets from http://www.microsoft.com/china and install it), which enables it spport the high strenth encryption and has a high security.

Q:

What to do under the circumstances of failing to establish the security conection with SSL gateway and failing to get reasons for the problems through service catalog ?

 

A:

This a common problen, please check-up according to following flow:

1. Whether SSL service is running or not;

2. Please confirm whether the accessing address is correct or not:https://SSL Server IP:SSL Server Port

3. Please check the network: whethen the network between user terminal and SSL is accessible. Use "ping" SSL gateway's IP at user terminal, if "ping" is not accessible, then ① whether "ping" of the other user terminals in the same network period is accessible. If it is "yes", there is something wrong in the etwork of the current computer; if it is "not", then turn to ②. ②If the current computer and SSL gateway are not in the same network period, the probably reason may be the wrong settings of default router in the SSL gateway. Please check it. Moreover,after correct settings, the power suppply of SSL gateway shall be turn off and restart. If it is still not accessible after restart and correct settings, please check whether "ping" is accessible between SSL and the computers in the same network. If it is accessible, the errors exist in the router or firewall (they are between the current computer and SSL gateway); if it is not accessible, then turn to③. ③Please check whether the IP of eth0 of SSL gateway is correct or not. If it is correct, then there is something wrong with network cards or network lines.

4. Please check the network:Whether the "ping" of user terminal is the same to "ping" of service port of SSL gateway. Please input "telnet SSL IP SSL Service Port (eg. telnet 192.168.1.6 443)at dos interface. If no suggestion appears and nothing is shown at dos interface, that means the path between user terminal and service port of SSL gateway is accessible; if "connecting to 192.168.1.6... unable to open the connection to host computer at port443 : connection failed" is shown,then please input "telnet SSL IP SSL Service Port”in another computer in the same network to confirm whether it is accessible. If it is accessible, that means the firewall has blocked the connection between user terminal and SSL gateway and it is necessary to open the SSL servive port of the firewall for extenal access. If it is not accessible, that means SSL gateway is not running. PLease check whether SSL service is running or not again. You can contact Koal Software for more details.

5. Please check whether the attributes of certificate collocated in SSL gateway has attributes like "Digital Signature" and "Key Agreement". If neither "Digital Signature" nor "Key Agreement" is available, plese contact CA provider at once. (such things happen seldomly.) The way to check the attribute is to change the extension name of the website certificate to"cer" and double-click "certificate attribute browser" on WINDOWS.
 
HOME ABOUT US PRESS CENTER PRODUCTS SUPPORT CONTACT US O A JOBS at KOAL SITEMAP
Copyright © 1998-2005 Shanghai Koal Software Co., Ltd. All Rights Reserved