<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: workspace agent sign-in error &amp;quot;unable to get local issuer certificate&amp;quot; in Workspace ONE Discussions</title>
    <link>https://communities.vmware.com/t5/Workspace-ONE-Discussions/workspace-agent-sign-in-error-quot-unable-to-get-local-issuer/m-p/1323301#M4579</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-family: Arial; font-size: 11.0pt;"&gt;This command can be run from the gateway-va or other va's, trying to verify certificate&lt;/P&gt;&lt;P style="font-family: Arial; font-size: 11.0pt;"&gt;Or from a machine that has openssl installed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Arial; font-size: 11.0pt; color: black;"&gt;&lt;SPAN style="background: white;"&gt;OpenSSL&amp;gt; s_client -connect connector-hostname:443 &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Apr 2014 20:11:28 GMT</pubDate>
    <dc:creator>rtindall</dc:creator>
    <dc:date>2014-04-23T20:11:28Z</dc:date>
    <item>
      <title>workspace agent sign-in error "unable to get local issuer certificate"</title>
      <link>https://communities.vmware.com/t5/Workspace-ONE-Discussions/workspace-agent-sign-in-error-quot-unable-to-get-local-issuer/m-p/1323298#M4576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are running Horizon Workspace 1.5 and Agents 1.5.2. &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;The users are Windows 7 linked clones. &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Workspace SSL cert is a GlobalSign cert. The full chain is presented on the load balancer and connector VA including the server, intermediate and root CA certs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;User access to the internet (ie to verify the Root CA) is via a proxy server that uses their AD credentials. IE is configured via group policy to use this proxy. proxy is bypassed for internal LAN connectivity to Workspace.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If a user opens the workspace URL &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://workspace.domain.org"&gt;https://workspace.domain.org&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; using Internet Explorer they get no SSL certificate errors and it validates the complete SSL chain.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;When the user opens the workspace agent they get an error prior to logging on "unable to get local issuer certificate". &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Once they accept this error and login they never see it again - unless they log out of workspace and need to log in again&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Is it possible that the workspace agent is not using the IE proxy configuration initially, hence the reason it cannot validate the SSL chain?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can we resolve this? Its not breaking anything but we are getting helpdesk calls sometimes about this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Mar 2014 12:05:43 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Workspace-ONE-Discussions/workspace-agent-sign-in-error-quot-unable-to-get-local-issuer/m-p/1323298#M4576</guid>
      <dc:creator>MMAgeek</dc:creator>
      <dc:date>2014-03-20T12:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: workspace agent sign-in error "unable to get local issuer certificate"</title>
      <link>https://communities.vmware.com/t5/Workspace-ONE-Discussions/workspace-agent-sign-in-error-quot-unable-to-get-local-issuer/m-p/1323299#M4577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you figure this out I would be curious to know the answer as I think I have the same "issue". Not really an issue as you click once and then it is gone but indeed always better to avoid those calls.&lt;/P&gt;&lt;P&gt;For me it started to happen as soon as I started using a wildcard certificate instead of a SAN cert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seb&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Mar 2014 16:23:23 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Workspace-ONE-Discussions/workspace-agent-sign-in-error-quot-unable-to-get-local-issuer/m-p/1323299#M4577</guid>
      <dc:creator>Seb1180</dc:creator>
      <dc:date>2014-03-20T16:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: workspace agent sign-in error "unable to get local issuer certificate"</title>
      <link>https://communities.vmware.com/t5/Workspace-ONE-Discussions/workspace-agent-sign-in-error-quot-unable-to-get-local-issuer/m-p/1323300#M4578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How many connectors do you have? Have you verified that the certificate you loaded for the Globalsign cert on the connectors as well?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Apr 2014 20:08:52 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Workspace-ONE-Discussions/workspace-agent-sign-in-error-quot-unable-to-get-local-issuer/m-p/1323300#M4578</guid>
      <dc:creator>rtindall</dc:creator>
      <dc:date>2014-04-23T20:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: workspace agent sign-in error "unable to get local issuer certificate"</title>
      <link>https://communities.vmware.com/t5/Workspace-ONE-Discussions/workspace-agent-sign-in-error-quot-unable-to-get-local-issuer/m-p/1323301#M4579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-family: Arial; font-size: 11.0pt;"&gt;This command can be run from the gateway-va or other va's, trying to verify certificate&lt;/P&gt;&lt;P style="font-family: Arial; font-size: 11.0pt;"&gt;Or from a machine that has openssl installed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Arial; font-size: 11.0pt; color: black;"&gt;&lt;SPAN style="background: white;"&gt;OpenSSL&amp;gt; s_client -connect connector-hostname:443 &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Apr 2014 20:11:28 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Workspace-ONE-Discussions/workspace-agent-sign-in-error-quot-unable-to-get-local-issuer/m-p/1323301#M4579</guid>
      <dc:creator>rtindall</dc:creator>
      <dc:date>2014-04-23T20:11:28Z</dc:date>
    </item>
  </channel>
</rss>

