メインコンテンツへスキップ

F5ネットワークロードバランサでSSL証明書の有効期限が切れているため、ノードのリブート後にオブジェクトストアを使用できない

Views:
51
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
core<a>2010057414</a>
Last Updated:

環境

  • ONTAP 9
  • StorageGRID
  • F5ネットワークロードバランサ

問題

  • ハードウェアの障害が原因でONTAPオンプレミスクラスタ内のノードがパニック状態になり、テイクオーバーされました。

  • ノードはリカバリされたが、ギブバックが失敗し、リブートしたノードが所有するアグリゲートにオブジェクトストアにアクセスできない。

cluster::> aggregate object-store show
  (storage aggregate object-store show)
Aggregate      Object Store Name Availability   Mirror Type
-------------- ----------------- -------------  -----------
...
node1_aggr2   NPH_StorageGRID   available      primary
node3_aggr1   NPH_StorageGRID   unavailable    primary
node3_aggr2   NPH_StorageGRID   available      primary

6/8/2024 08:53:51   NODE04     ERROR    Unable to connect to the object store "StorageGRID" from node 266af68c-6536-11e8-bcdd-xxxxxxxxxxxx. Reason: Connection unavailable.
6/8/2024 08:31:12   NODE04         ALERT         sfo.giveback.attemptExceeded: Attempts for automatic giveback of SFO aggregates exceeded the maximum number (3) of allowed attempts.
6/8/2024 08:30:36   NODE04         ALERT         sfo.giveback.failed: Giveback of aggregate node3_aggr2 failed due to destination check failed.
6/8/2024 08:30:36   NODE04         ALERT         sfo.sendhome.subsystemAbort: The giveback operation of 'node3_aggr2' was aborted by 'fabric pools'.
6/8/2024 08:30:36   NODE04         ERROR         gb.netra.ca.check.failed: Giveback of aggregate 'node3_aggr2' (uuid: 27f187b6-45f7-4125-b1ac-xxxxxxxxxxxx) failed due to Object store is not reachable on destination preventing object store access on the destination node.

  • ノードでクラスタ間LIFが正常に機能しており、オブジェクトストアにpingを送信できます。

  • HTTPSが使用され、SSL検証が有効になっています。

    cluster::> storage aggregate object-store config show -fields server,port
    object-store-name server                         port
    ----------------- ------------------------------ ----
    StorageGRID       storagegrid.domain.com         443

  • CA認証局と証明書のカスタム設定があります。

  • 有効期限が切れた証明書があります。

cluster::*> security certificate truststore check -server storagegrid.domain.com -vserver cluster

Error: command failed: Failed to verify server's certificate chain. Reason: certificate has expired

 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.