5
If it is suspected that a port is blocked it can be very useful to use a network capture utility like
Wireshark to analyze network traffic. With the capture utility capturing packets at the DSS server,
initiate a job from the device and capture the traffic. If no packets are seen at the network interface that
originate from the device then the port is being blocked in the network infrastructure and not on the
DSS server itself. But, if the traffic is blocked on the DSS server then what will be seen is an initial packet
coming in from the device that is repeated every 3 seconds for about 30 seconds. This is because the
packet sent from the device to start a communication with the DSS service reaches the network
adaptor, but the firewall prevents it from getting to the DSS service so the service never acknowledges
the incoming packet. The device, not getting an acknowledgement, will retry every 3 seconds until it
gives up after 30 seconds.
Errors in Certificate Validation
This section applies only to FutureSmart devices. FutureSmart devices communicate with DSS using a
SSL/ TLS secure channel which requires an exchange of certificates between the device and the DSS
server. The certificate that the DSS server gives to the device is a self-signed certificate with a date range
that starts when the DSS instance was installed.
Starting in FutureSmart firmware from November 2014 the FutureSmart devices have server certificate
validation enabled by default. This means that when an external server gives the device a certificate for
SSL/TLS communication the device checks the certificate to make sure it is valid.
The most common certificate validation error we have seen is due to date checking. The DSS server’s
certificate has a valid start date from when DSS was installed and an end date way in the future (more
than 20 years). If the device has an incorrectly set date, one that is outside of the range for valid dates
for the DSS server’s certificate, then certificate validation will fail. When certificate validation fails the
device is unable to initiate communication with the DSS server.
The FutureSmart devices will log any certificate validation failures in the device’s event log. If jobs are
failing the manual bidi test should be run. If it fails, the event log of the device should be checked for
certificate validation errors. The error code to look for is 44.A0.A1.
Comentários a estes Manuais