Jump to content

Recommended Posts

Posted (edited)

Hi all,

 

This started to be an issue sometime before the holidays

 

It used to work fine and the cert hasn't expired. I'm not sure if a recent papercut update has caused it.

 

However, when i attempt to log into our papercut console https://servername:9192 or via https://ipaddress:9192 i'm getting a "not secure" error.

 

The cert is in the "trusted root certification authorities" and i re imported it also but it still doesn't work

 

Any ideas?

 

the error is "NET::ERR_CERT_COMMON_NAME_INVALID"

 

cheers

Edited by Jaan
Posted

What name is the Cert using? As it wouldn’t normally cover an IP and name st once so one of those errors would be expected. Only what is covered under the common name would apply and show as non-error

 

But in terms of you’re comment about the Cert being in trusted root do you mean on the printnserver? As papercut has its own Cert store and doesn’t use MMC style ones

 

Steve

Posted

The cert name is that of the print server. in the past when we got https errors on the console, we just added the cert to our machines trusted root and the https errors went away.

 

it's the same for all our tech machines and even the server, all currently have the https errors.

 

just wondering if this will help me: https://www.papercut.com/kb/Main/SSLWithKeystoreExplorer#part-two-generating-a-certificate-signing-request-csr-and-importing-the-response

 

however this step confuses me "3. Apply for a certificate with your Certificate Authority (CA) by providing them the CSR."

Posted
What name is the Cert using? As it wouldn’t normally cover an IP and name st once so one of those errors would be expected. Only what is covered under the common name would apply and show as non-error

 

But in terms of you’re comment about the Cert being in trusted root do you mean on the printnserver? As papercut has its own Cert store and doesn’t use MMC style ones

If OP is seeing this error in browser, then adding the cert to the local Trusted Root Cert Authority is correct action assuming the cert is actually correct.

 

I believe you're referring to changing the cert issued by Papercut, which is indeed a custom store.

 

However your first comment is the one I suspect will be the issue here.

Posted
If OP is seeing this error in browser, then adding the cert to the local Trusted Root Cert Authority is correct action assuming the cert is actually correct.

 

I believe you're referring to changing the cert issued by Papercut, which is indeed a custom store.

 

However your first comment is the one I suspect will be the issue here.

 

Adding a Cert locally that’s still for the wrong name wouldn’t resolve the wrong common name unless I’m missing something. The error is invalid common name, not trust related

 

The way you’re talking about would be if it’s a non trusted locally generated Cert etc that the machine doesn’t know about?

 

Steve

Posted

Sorry, simultaneously posted with OP.

@Jaan is the cert name JUST the servername (ie SvrPrint) or is it the FQDN (SvrPrint.myschool.local)?

 

And are you browsing to the matching URL?

 

(Our vmware cert is vsphereserver.myschool.local so I get ERR_CERT_COMMON_NAME_INVALID if I browse https://vsphereserver/somepage)

Posted
Is it's a browser error i am receiving. The cert name hasn't changed. i thought the cert was automatically generated by papercut when installed. Maybe it was a papercut update that has caused the issue?
Posted

Cert name is the server name eg print-server not print-server.domain.net

 

the url from which i'm getting the error is: https://print-server.domain.net:9192/admin

 

the cert expires in 2034 and is the same one we've been using since we installed papercut years ago. we've always just dumped it into our machines trusted root certification authorities.

 

cheers

Posted (edited)

Yep that’s as expected. Papercut generates it based on server name by default, so if you want it FQDN you need to change it to that as per their documentation - https://www.papercut.com/support/resources/manuals/ng-mf/common/topics/tools-ssl-key-generation-recreate-self-signed.html

 

The only other thing I guess you may have done previously, is changed the server name in papercut config to be the FQDN rather than server name, and you might have overwritten that with an upgrade. In Papercut admin custom options what do you have the server name set as now?

 

But from what you’ve explained so far, nothing seems wrong as that’s working as expected

 

Edit - just saw your reply, can you upload a screenshot of the browser error with url and the Cert name showing on the actual Cert (from the browser NOT what you deploy as these could be a different Cert) without seeing what you see hard to tell what you’re getting

 

Steve

Edited by Steve21
Posted
cheers

 

[ATTACH=CONFIG]65277[/ATTACH]

 

[ATTACH=CONFIG]65278[/ATTACH]

 

[ATTACH=CONFIG]65279[/ATTACH]

 

[ATTACH=CONFIG]65280[/ATTACH]

 

[ATTACH=CONFIG]65281[/ATTACH]

 

Thanks,

Sorry should have said before but on that first screen if you click the advanced button what’s that message say?

 

As normally it’s say something like server can’t prove its print-server as it’s issued from blah etc

 

Steve

Posted

That error is more about how Chrome/Edge process it, as it’s got no SAN applied to the Cert it says, even though it’s a valid Cert it’ll still complain. I’m guessing your Cert was created before Google made those changes previously

 

You could regenerate the Cert to add a SAN on, alternatively if it’s just for you techies you could disable the check in Chrome etc but obviously be nicer to fix it fully

 

Steve

Posted
That error is more about how Chrome/Edge process it, as it’s got no SAN applied to the Cert it says, even though it’s a valid Cert it’ll still complain. I’m guessing your Cert was created before Google made those changes previously

 

You could regenerate the Cert to add a SAN on, alternatively if it’s just for you techies you could disable the check in Chrome etc but obviously be nicer to fix it fully

 

Steve

 

That makes sense, IIRC it was about Chrome 100 it started so makes sense.

 

Can i regenerate the cert from Papercut which includes the SAN?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...