Server Certificate Troubleshooting

Refer to these troubleshooting steps if you changed the server certificate used by the Transfer Server or Gateway Administrator server.

After any changes you make to server certificate setup, always perform both of the following before retesting:

  1. Close all browser windows.

  2. Restart the server whose certificate you are configuring. See Start and Stop the Reflection Transfer Server and Start and Stop the Reflection Gateway Administrator Service.

Certificate warning still appears

  • Did you close all browser windows and restart the server before retesting?

  • Does the server name in the URL you are using match the server name(s) in the certificate?

Browser cannot display the web page

  • Did you specify the correct password for servletengine.ssl.keystorepassword?

  • Is the keystore file in the location specified for servletengine.ssl.keystore?

  • Did you migrate your PKCS#12 or JKS keystore to BCFKS format? See Migrate PKCS#12 or JCEKS keystores to BCFKS keystores.

Login is successful, but error messages appear in the log file

  • The message "javax.net.ssl.SSLException: Fatal Alert received: Bad Certificate" appears repeatedly in the server log file.

    This exception is most likely to occur if the Transfer Server has not been updated to trust a new Gateway Administrator certificate. To resolve this issue, from the Reflection Secure Shell Proxy console, go to the Reflection Gateway Users pane and click Activate and verify.