ONTAP でのリブート後に HTTPS / SSL 接続が失敗する
環境
- ONTAP 9
- HTTPS/SSL
- クラスタ ピアリング
- AutoSupport
- System Manager
問題
- ノードのリブート後、 HTTPS / SSL を使用するサービスに接続できません。
- では障害が発生する可能性があります(ただし、これらに限定されません)。
- AutoSupport
- クラスタ ピアリング
- System Manager
- さまざまなログおよびコマンド出力に表示される SSL エラーメッセージ:
「 AutoSupport check show-details 」コマンド:
Cluster::> autosupport check show-details
Node: cluster-01
Category: http-https
Component: http-put-destination
Status: failed
Detail: HTTP/S PUT connectivity check failed for destination:
https://support.netapp.com/put/AsupPut/. Error: SSL
connect error
Component: http-post-destination
Status: failed
Detail: HTTP/S POST connectivity check failed for destination:
https://support.netapp.com/asupprod/post/1.0/postAsup.
Error: SSL connect error
Notifyd ログ:
[kern_notifyd:info:1530] (category: 1530:0:deliver) (emittime: 8/31/2021 01:44:52) (message: TLSv1.2 (OUT), TLS header, Certificate Status (22):)
[kern_notifyd:info:1530] (category: 1530:0:deliver) (emittime: 8/31/2021 01:44:52) (message: TLSv1.2 (OUT), TLS handshake, Client hello (1):)
[kern_notifyd:info:1530] (category: 1530:0:deliver) (emittime: 8/31/2021 01:44:52) (message: error:0E065068:configuration file routines:STR_COPY:variable has no value)
[kern_notifyd:info:1530] (category: 1530:0:deliver) (emittime: 8/31/2021 01:44:52) (message: Marked for [closure]: Failed HTTPS connection)
[kern_notifyd:info:1530] (category: 1530:0:deliver) (emittime: 8/31/2021 01:44:52) (message: multi_done)
00000015.0062e0fa 001c17d5 Tue Aug 31 2021 01:44:53 -04:00 [kern_notifyd:info:1530] (category: 1530:0:deliver) (emittime: 8/31/2021 01:44:52) (message: The cache now contains 0 members)
[kern_notifyd:info:1530] (category: 1530:0:deliver) (emittime: 8/31/2021 01:44:52) (message: Closing connection 0)
APACHE-ERRORログ
[ssl:emerg] [pid 67509:tid 34389163776] AH02562: Failed to configure certificate 127.0.0.1:0 (with chain), check /mroot/etc/vserver_0000000000/certificates/ssl/server/UUID/server.crt
[ssl:emerg] [pid 67509:tid 34389163776] SSL Library Error: error:0E065068:configuration file routines:STR_COPY:variable has no value (line 12)
{ssl:error] [pid 67509:tid 34389163776] [client 10.0.0.5:30001] [vserver 0000000000] Failed to initialize SSL context
[ssl:notice] [pid 67509:tid 34389171456] [client 10.0.0.5:30001] [vserver 0000000000] No server certificate chain is configured for this vserver
[ssl:notice] [pid 67509:tid 34389171456] [client 10.0.0.5:30001] [vserver 0000000000] Certificate-based client authentication is not configured for this vserver