locked
SfB client in MAC RRS feed

  • Question

  • hi,

    I have a authentication problem with SfB client (v 16.3.240) on mac (OS X El Capitan 10.11.6). The CA root was imported in the machine but, I try to sign in with credentials of SfB and the client stay loading or search UCWA services. If the same user moves to Lync server 2013 pool, the sign in is succesfull in the same client.
    When search the ews services https://pool.domain.com in mozilla browser, this prompt "no trusted certificate", but the certificate is configured to trust always in System container (two level CA).

    MOZILLA PROMPT

    SYSTEM CONTAINER

    Firewall and proxies turn off in the client machine.
    DNS resolution is succesfull.

    Thanks for you feedback.


    Daniel Muñoz

    Monday, April 10, 2017 7:20 PM

Answers

  • Hi Alice,

    After investigate the issue, i know what is the problem. This is a issue for SHA1 decommissioning of browser providers, in this case google chrome. So the best practice is update de Algorithm of de certificate to SHA256 (internal CA).

    Thanks for you comments!!


    Daniel Muñoz

    • Marked as answer by Jacobo Muñoz Wednesday, June 7, 2017 6:48 PM
    Wednesday, June 7, 2017 6:48 PM

All replies

  • Hi Jacobo,

    Could you please translate the text message in the screenshot into English?

    In order to narrow down the issue, please help us confirm the following questions:

    1. Did the issue only appear on the specific client?
    2. Where is the affected user, in SFB 2015 pool?
    3. Please also try to use another user test if there is the same issue.

    Regards,

    Alice Wang


    Please remember to mark the replies as an answers if they help and unmark them if they provide no help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Tuesday, April 11, 2017 2:39 AM
  • Hi Alice,

    Into de screen shot:

    Connection no secure - Add to security  exception for this site.

    Answer for your questions:

    1. Did the issue only appear on the specific client?

        The issue appear in any client and machine mac.

    2. Where is the affected user, in SFB 2015 pool?

        Yes, the issue only affect registrar users in pool SfB 2015.

    3. Please also try to use another user test if there is the same issue.

        I'm try to another user and machine mac in my office and this sign in succesfull, but in an customer machine     can not sign in to same user.

    Regards



    Daniel Muñoz

    Tuesday, April 11, 2017 12:50 PM
  • Answer for your questions:

    1. Did the issue only appear on the specific client?

        The issue appear in any client and machine mac.

    2. Where is the affected user, in SFB 2015 pool?

        Yes, the issue only affect registrar users in pool SfB 2015.

    3. Please also try to use another user test if there is the same issue.

        I'm try to another user and machine mac in my office and this sign in succesfull, but in an customer machine     can not sign in to same user.

    Hi Jacobo,

    Did you mean the issue only appear on the specific user?

    If the issue only appeared on the specific user, please try to compare user attributes in AD between the  affected user and other normal users.

    If all users had this issue, please renew  the certificate on SFB FE server.



    Regards,

    Alice Wang


    Please remember to mark the replies as an answers if they help and unmark them if they provide no help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    • Proposed as answer by Alice-Wang Friday, April 14, 2017 9:30 AM
    Friday, April 14, 2017 9:03 AM
  • Hi Alice,

    After investigate the issue, i know what is the problem. This is a issue for SHA1 decommissioning of browser providers, in this case google chrome. So the best practice is update de Algorithm of de certificate to SHA256 (internal CA).

    Thanks for you comments!!


    Daniel Muñoz

    • Marked as answer by Jacobo Muñoz Wednesday, June 7, 2017 6:48 PM
    Wednesday, June 7, 2017 6:48 PM