<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://ucvug.nl/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Search results matching tag ': Office Communications Server 2007 R2'</title><link>http://ucvug.nl/search/SearchResults.aspx?a=1&amp;o=DateDescending&amp;tag=:+Office+Communications+Server+2007+R2&amp;orTags=0</link><description>Search results matching tag ': Office Communications Server 2007 R2'</description><dc:language>en-US</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Your session was ended… Error code:0-0-18100-2-0</title><link>http://ucvug.nl/blogs/joachimfarla/archive/2009/06/02/your-session-was-ended-error-code-0-0-18100-2-0.aspx</link><pubDate>Tue, 02 Jun 2009 19:42:00 GMT</pubDate><guid isPermaLink="false">a3704718-45ac-4a35-ab03-60d6ef26914b:202</guid><dc:creator>admin</dc:creator><description>&lt;p&gt;The last couple of days I was working at a customer side to deploy OCS R2 EE Consolidated Topology, CWA R2 server and OCS R2 Edge. Starting of with OCS R2 EE without any problems. The OCS R2 Documentation is btw very nice to read and makes your OCS R2 deployment much more easier than ever before. &lt;/p&gt;
&lt;p&gt;When installing the CWA R2 server the real problems begun. Strange enough this specific error was never seen before. And also search via &lt;a href="http://www.bing.com/"&gt;bing&lt;/a&gt; on this specific error nothing useful returned. Not &amp;ldquo;bings&amp;rdquo; fault but the error is not seen quite often. Some Spanish and Russian site did write feedback in the OCS R2 forums but nothing useful and still not helping me resolving this issue. &lt;/p&gt;
&lt;p&gt;Issue:&lt;/p&gt;
&lt;p&gt;When setting up the CWA R2 server and installing the bits for CWA R2 and after that requesting my certificate with the following paramaters:&lt;/p&gt;
&lt;p&gt;&lt;b&gt;LcsCmd.exe /Cert /Action:Request /sn:im.contoso.com /san: im.contoso.com,download.im.contoso.com,as.im.contoso.com /ca:ca-server.contoso.com /OU:OCSServers /org:Contoso /country:US /city:Redmond &lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;/state:WA /friendlyName:CWA_Certificate /exportable:TRUE&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;the webuser was still unable to connect to the pool (pool01.contoso.com). Error message: &lt;/p&gt;
&lt;p&gt;&lt;span style="color:#ff0000;"&gt;&lt;strong&gt;Error code:0-0-18100-2-0&lt;/strong&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;So I verified:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Can the CWA R2 server connect to the OCS R2 EE pool server? Start: &lt;strong&gt;cmd, nslookup, set type=srv, _sipinternaltls._tcp.contoso.com&lt;/strong&gt; &lt;/li&gt;
&lt;li&gt;Can I telnet to port 5061 on the pool server. &lt;strong&gt;telnet pool01.contoso.com 5061&lt;/strong&gt; (blank page returned) &lt;/li&gt;
&lt;li&gt;Does it make sense when I change the default port 5061 back to 5060? &lt;/li&gt;
&lt;li&gt;Does it make sense to enabling Server to Server compression on the Pool/Front End properties on the Compression tab? &lt;/li&gt;
&lt;li&gt;Does it make sense to run the Logging Tool on the CWA R2 server? &lt;/li&gt;
&lt;li&gt;Does the CWA R2 and OCS R2 server both share the correct Root Certificate Chain? &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The last two options will be the best choice for investigating to resolve this issue. After some drill down&amp;rsquo;s in the CWA R2 Diagnostic Logging I saw some error saying:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt; [UCWeb.exception] (endpoint)----- &amp;lt;epid=15(&lt;a href="mailto:usera@contoso.com"&gt;sip:usera@contoso.com&lt;/a&gt;) &lt;br /&gt;UCWEB Failure: Code=OcsFailureResponse, SubCode=OcsOperationTimeout, Reason= &lt;br /&gt;Microsoft.Rtc.Internal.UCWeb.Utilities.UCWException: &lt;span style="color:#ff0000;"&gt;This operation has timed out&lt;/span&gt;. ---&amp;gt; Microsoft.Rt &lt;br /&gt;c.Signaling.OperationTimeoutException: This operation has timed out. &lt;br /&gt;&amp;nbsp;&amp;nbsp; at Microsoft.Rtc.Signaling.SipAsyncResult`1.ThrowIfFailed() &lt;br /&gt;&amp;nbsp;&amp;nbsp; at Microsoft.Rtc.Signaling.Helper.EndAsyncOperation[T](Object owner, IAsyncResult result) &lt;br /&gt;&amp;nbsp;&amp;nbsp; at Microsoft.Rtc.Collaboration.LocalEndpoint.EndEstablish(IAsyncResult result) &lt;br /&gt;&amp;nbsp;&amp;nbsp; at Microsoft.Rtc.Internal.UCWeb.UCWAuthenticatedEndpoint.OotyUserEndpointEstablish_callback(IAsyn &lt;br /&gt;cResult asyncResult)&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;and:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;( 0000000002DCBCA1 )Endpoint unbound: &amp;lt;endpointId=15&amp;gt;, &amp;lt;SipUri=sip:usera@contoso.com&amp;gt;TL_WARN (TF_COMPONENT) UCWeb (UCWEndpointManager.UnBind:endpointmanager.cs(200))&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [0]0DBC.0C44 &lt;br /&gt;::05/28/2009-14:21:57.704.00000004 &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ( 0000000002DCBCA1 )Unbind:&lt;span style="color:#ff0000;"&gt; Endpoint not found&lt;/span&gt;: &amp;lt;endpointId=15&amp;gt;, &amp;lt;SipUri=sip:usera@contoso.co &lt;br /&gt;m&amp;gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;For me this error was indicating that there was something wrong on the &lt;span style="text-decoration:underline;"&gt;certificate&lt;/span&gt; side. When setting up the CWA R2 server, two different certificates are used. One certificate for MTLS usage and one certificate for public SSL web access. The first certificate is used for server-to-server encryption (server to server communication) and the second certificate is used as web server certificate used on your internal or external Virtual CWA R2 website. &lt;/p&gt;
&lt;p&gt;In my specific case the CWA R2 server was used for &lt;em&gt;public&lt;/em&gt; remote information workers connecting all over the world so we decided to request an third party certificate. &lt;/p&gt;
&lt;p&gt;Resolution or workaround:&lt;/p&gt;
&lt;p&gt;(Step 1)&lt;/p&gt;
&lt;p&gt;Make sure the request a Web Server certificate from a Windows Server CA procedure is going well. So replace the lcscmd.exe command line to your specific configuration:&lt;/p&gt;
&lt;p&gt;&lt;b&gt;LcsCmd.exe /Cert /Action:Request /sn:im.contoso.com /san: im.contoso.com,download.im.contoso.com,as.im.contoso.com /ca:ca-server.contoso.com /OU:OCSServers /org:Contoso /country:US /city:Redmond &lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;/state:WA /friendlyName:CWA_Certificate /exportable:TRUE&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;(Step 2) &lt;/p&gt;
&lt;p&gt;Depending on your type of Windows CA (hopefully Windows Server 2008) &lt;em&gt;issue&lt;/em&gt; the certificate if needed. Open the Certificate Authority MMC on the CA server en double click the certificate who is now under the folder &amp;ldquo;&lt;em&gt;issued certificates&lt;/em&gt;&amp;rdquo; and export the entire certificate to a P7B extension. &lt;/p&gt;
&lt;p&gt;(Step 3)&lt;/p&gt;
&lt;p&gt;On the Communicator Web Access server, click &lt;b&gt;Start&lt;/b&gt;, and then click &lt;b&gt;Run&lt;/b&gt;. In the &lt;b&gt;Run&lt;/b&gt; dialog box, type &lt;b&gt;mmc&lt;/b&gt;, and then click &lt;b&gt;OK&lt;/b&gt;.On the &lt;b&gt;File&lt;/b&gt; menu, click &lt;b&gt;Add/Remove Snap-in&lt;/b&gt;.In the &lt;b&gt;Add/Remove Snap-in&lt;/b&gt; dialog box, click &lt;b&gt;Add&lt;/b&gt;.In the list of &lt;b&gt;Available Standalone Snap-ins&lt;/b&gt;, click &lt;strong&gt;Certificates&lt;/strong&gt;.&lt;strong&gt; &lt;/strong&gt;Click &lt;b&gt;Add&lt;/b&gt;.In the &lt;b&gt;Certificates Snap-in&lt;/b&gt; dialog box click &lt;b&gt;Computer account&lt;/b&gt;, and then click &lt;b&gt;Next&lt;/b&gt;.In the &lt;b&gt;Select Computer&lt;/b&gt; dialog box, ensure that the &lt;b&gt;Local computer: (the computer this console is running on)&lt;/b&gt; check box is selected, and then click &lt;b&gt;Finish&lt;/b&gt;.Click &lt;b&gt;Close&lt;/b&gt;, and then click &lt;b&gt;OK&lt;/b&gt;. In the left pane of the &lt;b&gt;Certificates&lt;/b&gt; console, expand &lt;b&gt;Certificates (Local Computer)&lt;/b&gt;, expand &lt;b&gt;Trusted Root Certification Authorities&lt;/b&gt;, and then click &lt;b&gt;Certificates&lt;/b&gt;. Right click the &lt;b&gt;Trusted Root Certification Authorities&lt;/b&gt; and import the response file (P7B issued by your CA server). And confirm that the certificate is located in this folder.&lt;/p&gt;
&lt;p&gt;(Step 4)&lt;/p&gt;
&lt;p&gt;Make sure you also copy the certificate to your personal store in the same interface like step 3. Make sure the issuing CA root certificate is also there. &lt;/p&gt;
&lt;p&gt;(Step 5)&lt;/p&gt;
&lt;p&gt;Double clock the certificate you copied and make sure that the certification path is showing you &lt;strong&gt;both&lt;/strong&gt; the CA server and the issued certificate used for MTLS. &lt;/p&gt;
&lt;p&gt;Test your connection again by hitting the CWA URL and you will see that the problem is solved. Any questions please contact me if you want.&lt;/p&gt;
&lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:cd031916-536a-4d2a-9a2e-c44685661c78" style="padding-bottom:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;float:none;padding-top:0px;"&gt;Technorati Tags: &lt;a rel="tag" href="http://technorati.com/tags/Office+Communications+Server+2007+R2"&gt;Office Communications Server 2007 R2&lt;/a&gt;,&lt;a rel="tag" href="http://technorati.com/tags/CWA+R2"&gt;CWA R2&lt;/a&gt;,&lt;a rel="tag" href="http://technorati.com/tags/Error+code%3a0-0-18100-2-0"&gt;Error code:0-0-18100-2-0&lt;/a&gt;,&lt;a rel="tag" href="http://technorati.com/tags/MTLS"&gt;MTLS&lt;/a&gt;,&lt;a rel="tag" href="http://technorati.com/tags/OCS+certificates"&gt;OCS certificates&lt;/a&gt;,&lt;a rel="tag" href="http://technorati.com/tags/P7B"&gt;P7B&lt;/a&gt;,&lt;a rel="tag" href="http://technorati.com/tags/lcscmd"&gt;lcscmd&lt;/a&gt;,&lt;a rel="tag" href="http://technorati.com/tags/OCS+R2"&gt;OCS R2&lt;/a&gt;&lt;/div&gt;</description></item></channel></rss>