IBM Support

XXA-CON-0011 CAM-CRP-1072 while testing SSL-enabled SSAS data-source

Troubleshooting


Problem

When testing an XMLA connection to an SSL-enabled SSAS datasource, an XXA-CON-0011 and CAM-CRP-1072 error is received, indicating that the host name, peer name and IP address do not match a configured Server Common Name.

Symptom

XXA-CON-0011 An I/O error occurred: java.security.cert.CertificateException:  Subject Alternative Name of SSL certificate <certificate Subject appears here> is empty. And the peer hostname < hostname appears here>; and FQDN <FQDN appears here>; and IP address <IP address appears here>; does not match configured Server Common Name <certificate Server Common Name appears here>

Cause

The certificate has an incorrect domain name

Diagnosing The Problem

Review each certificate in the chain of trust for the SSAS server, to ensure that the domain names of the database server match what has been issued. There are tools available for all platforms which allow for a certificate to be viewed, as well as online certificate decoders. Consult your OS documentation / web-resources.

Resolving The Problem

Ensure that all certificates involved in the SSAS chain of trust, up to the root-certificate, match the domain name of the servers.. Consult with your certification authority to arrange that they re-issue certificates with correct domain names.

[{"Line of Business":{"code":"LOB10","label":"Data and AI"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSTSF6","label":"IBM Cognos Analytics"},"ARM Category":[{"code":"a8m50000000Cl6nAAC","label":"Installation and Configuration->Data Sources"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version(s)"}]

Document Information

Modified date:
02 November 2020

UID

ibm16357939