You are viewing limited content. For full access, please sign in.

Question

Question

RIO 9.2.1 - Configure a master license SSL/TLS error

asked on July 13, 2015

Receiving the following error when trying to activate the master license for a Rio 9.2.1 install

0 0

Answer

SELECTED ANSWER
replied on July 13, 2015 Show version history

Similar to License Manager 8.3, Directory Server needs to be able to contact the Laserfiche activation server to perform an activation from a key. This previous post on the topic has some suggestions for how to handle this issue, as does this post. Your options are to make firewall exceptions (one for activation.laserfiche.com on port 443 and one for the GoDaddy Certificate Revocation IP), or to activate the license from a machine that has a less strict firewall, as described in KB1012198

Edit: it's been brought to my attention that newer Windows machines (8.1, Server 2012r2) may not have GoDaddy as a trusted root certificate authority, which would also cause issues with the SSL connection.

0 0
replied on July 13, 2015

We don't control the firewall at the site of the activation.laserfiche.com server. This is the site we are reaching out to on ports. You don't open ports for return traffic.

 

Here are the open ports on the activation.laserfiche.com server.

 

20/tcp   closed ftp-data
21/tcp   open   ftp
25/tcp   open   smtp
80/tcp   open   http
443/tcp  open   https
554/tcp  open   rtsp
1026/tcp open   LSA-or-nterm
1027/tcp open   IIS
1028/tcp open   unknown
1030/tcp open   iad1
1433/tcp open   ms-sql-s
1801/tcp open   msmq
2103/tcp open   zephyr-clt
2105/tcp open   eklogin
2107/tcp open   msmq-mgmt
2121/tcp open   ccproxy-ftp
8080/tcp closed http-proxy

 

0 0
replied on July 13, 2015

There are cases where outbound traffic on these ports are blocked (very high security networks), or the firewall is stateless and thus inbound traffic must be specifically allowed.

Regardless, it seems the recent issues with connecting to the activation server are more likely due to the GoDaddy certificate not being trusted, as Miruna mentioned here and I described in my edit.

0 0

Replies

replied on July 13, 2015

All suggested ports were open - we ended up having to activate the license from one of our local workstations, and then import the .licx license file on the actual Rio Directory Server.

0 0
You are not allowed to follow up in this post.

Sign in to reply to this post.