Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products

Dell Technologies VxRail: Node tilføjer NIC-konfiguration SSL: CERTIFICATE_VERIFY_FAILED

Summary: Dell Technologies VxRail: Node tilføjer NIC-konfiguration SSL: CERTIFICATE_VERIFY_FAILED Observeret på version 7.0.350.

This article applies to   This article does not apply to 

Symptoms

Under udførelse af en nodetilf tilføjelse kan vi ikke gå videre til konfigurationssiden for NIC.
VxRail version 7.0.350.
 

Fejllog:

22-04-28T05:33:31.194+0000 ERROR [pool-69-thread-1] com.vce.commons.domainowner.graphq.DefaultQueryExecutorImpl DefaultQueryExecutorImpl.filterOutErrorData:173 - Errors in do-host responsFQDN:9090 ssl: [[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:
852)]","locations":[{"line":1,"column":1542,"sourceName":null}],"description":null,"validationErrorType":null,"queryPath":null,"errorType":null,"path":["configuredHosts","0","hardware","pos
ition","rackName"],"extensions":null}


Curl-kontrol:

vxrm # curl --capath /var/lib/vmware-marvin/trust/lin --user root -X GET -H "Content-Type: application/json" -d '{}' https://ServerName.site.lab:9090/rest/ps/private/v1/misc/certservice/certs
Enter host password for user 'root':
curl: (35) error:14094410:SSL routines:ssl3_read_bytes:sslv3 alert handshake failure

Cause

SSL-handshake mellem ESXI og VXRM mislykkes.

 

 

Resolution

Kør nedenstående kommandoer for at bekræfte certifikatproblemet.
Kontroller og opdater ESXi-certifikaterne vha. VMware-dokumentationen nedenfor:

1. Kør nedenstående kommando for at teste ESXi-værtsforbindelsen, og hent hele outputtet:
vxm: # openssl s_client -crl_check_all -CApath /var/lib/vmware-marvin/trust/lin/ -connect :443

2. Kør nedenstående kommando for at teste ESXi-værtsforbindelsen, og hent hele outputtet:
vxm: # openssl s_client -crl_check -CApath /var/lib/vmware-marvin/trust/lin/ -connect :443

3. Kør nedenstående kommando for at teste ESXi-værtsforbindelsen, og hent hele outputtet:
vxm: # openssl s_client -CApath /var/lib/vmware-marvin/trust/lin/ -connect :443
Example output:
Verify return code: 0 (ok)
Or,
Verify return code: 12 (CRL has expired)


Gennemse VMware-dokumentationen for at forny og opdatere ESXi-certifikaterne:

– Forny og opdater ESXi-certifikater https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-ECFD1A29-0534-4118-B762-967A113D5CAA.html. Linkikon for tredjepart
- Kør den nyeste version af cert_util.py i kb nedenfor VxRail: Sådan importeres vCenter SSL-certifikat manuelt på VxRail Manager

 

Affected Products

VxRail, VxRail Appliance Family, VxRail Appliance Series