Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products

Dell Technologies VxRail:节点添加 NIC 配置 SSL:CERTIFICATE_VERIFY_FAILED

Summary: Dell Technologies VxRail:节点添加 NIC 配置 SSL:CERTIFICATE_VERIFY_FAILED 在版本 7.0.350 上观察到。

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

在执行节点添加时,我们无法通过 NIC 配置页面。
VxRail 版本 7.0.350。
 

错误日志:

22-04-28T05:33:31.194+0000 ERROR [pool-69-thread-1] com.vce.commons.domainowner.graphq.DefaultQueryExecutorImpl DefaultQueryExecutorImpl.filterOutErrorData:173 - Errors in do-host responsFQDN:9090 ssl: [[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:
852)]","locations":[{"line":1,"column":1542,"sourceName":null}],"description":null,"validationErrorType":null,"queryPath":null,"errorType":null,"path":["configuredHosts","0","hardware","pos
ition","rackName"],"extensions":null}


Curl 检查:

vxrm # curl --capath /var/lib/vmware-marvin/trust/lin --user root -X GET -H "Content-Type: application/json" -d '{}' https://ServerName.site.lab:9090/rest/ps/private/v1/misc/certservice/certs
Enter host password for user 'root':
curl: (35) error:14094410:SSL routines:ssl3_read_bytes:sslv3 alert handshake failure

Cause

ESXI 和 VXRM 之间的 SSL 握手失败。

 

 

Resolution

运行以下命令以验证证书问题。
使用下面的 VMware 文档检查和更新 ESXi 证书:

1.运行以下命令以测试 ESXi 主机连接,并捕获整个输出:
vxm: # openssl s_client -crl_check_all -CApath /var/lib/vmware-marvin/trust/lin/ -connect :443

2.运行以下命令以测试 ESXi 主机连接,并捕获整个输出:
vxm: # openssl s_client -crl_check -CApath /var/lib/vmware-marvin/trust/lin/ -connect :443

3.运行以下命令以测试 ESXi 主机连接,并捕获整个输出:
vxm: # openssl s_client -CApath /var/lib/vmware-marvin/trust/lin/ -connect :443
Example output:
Verify return code: 0 (ok)
Or,
Verify return code: 12 (CRL has expired)


查看 VMware 文档以续订和刷新 ESXi 证书:

更新和刷新 ESXi 证书 https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-ECFD1A29-0534-4118-B762-967A113D5CAA.html。第三方链接图标
- 在 VxRail 下面以 kb 为单位运行最新版本的 cert_util.py:如何在 VxRail Manager 上手动导入 vCenter SSL 证书

 

Affected Products

VxRail, VxRail Appliance Family, VxRail Appliance Series
Article Properties
Article Number: 000198975
Article Type: Solution
Last Modified: 19 May 2023
Version:  4
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.