VxRail: M2M-Switch kann während des Upgrades oder der Node-Erweiterung nicht auf dem Host festgelegt werden

Zusammenfassung: VxRail-Clusterupgrade oder Node-Erweiterung ist bei Hosteinstellung M2M-Switch fehlgeschlagen

Dieser Artikel gilt für Dieser Artikel gilt nicht für Dieser Artikel ist nicht an ein bestimmtes Produkt gebunden. In diesem Artikel werden nicht alle Produktversionen aufgeführt.

Symptome

Wenn Sie ein Clusterupgrade auf 7.0.350 oder eine Node-Erweiterung auf VxRail 7.0.350 durchführen, wird in short.term.log oder lcm-web.log der folgende Fehler angezeigt:

2022-12-02-11:36:28 microservice.do-host "[2022-12-02 11:36:28,557: INFO/ForkPoolWorker-18] Input url is qualified for certificate verification: https://<Host FQDN>:9090/rest/ps/private/v1/misc/certservice/mtls with vxm cert:None"
2022-12-02-11:36:28 microservice.do-host "[2022-12-02 11:36:28,878: INFO/ForkPoolWorker-18] [M2M] operation response from linzi: {""StatusCode"": 200, ""Message"": ""OK"", ""Details"": ""mTLS has been turned to 'ON'""}"
2022-12-02-11:36:29 microservice.do-host "[2022-12-02 11:36:29,880: INFO/ForkPoolWorker-18] [M2M]Waiting for linzhi status has been changed, try 1 times"
2022-12-02-11:36:29 microservice.do-host "[2022-12-02 11:36:29,880: INFO/ForkPoolWorker-18] [M2M]Show mtls status on host:<Host FQDN>"
2022-12-02-11:36:29 microservice.do-host "[2022-12-02 11:36:29,880: INFO/ForkPoolWorker-18] SKIP_CRL and get_crl_verify_level = 0"
2022-12-02-11:36:29 microservice.do-host "[2022-12-02 11:36:29,940: WARNING/ForkPoolWorker-18] Occur SSLError when sending linzhi request with read_type:VxmCertReadType.NORMAL, the error is HTTPSConnectionPool(host='<Host FQDN>', port=9090): Max retries exceeded with url: /rest/ps/private/v1/misc/certservice/mtls (Caused by SSLError(SSLError(1, '[SSL: SSLV3_ALERT_HANDSHAKE_FAILURE] sslv3 alert handshake failure (_ssl.c:852)'),)), retry next in [<VxmCertReadType.NORMAL: 'normal'>]"
2022-12-02-11:36:29 microservice.do-host "[2022-12-02 11:36:29,940: WARNING/ForkPoolWorker-18] [M2M]change m2m status error:Failed to send Linzhi request due to SSLError, Please check if vxm cert: are correct, will retry automatically"
.
022-12-02-11:41:31 microservice.do-host "[2022-12-02 11:41:31,375: ERROR/ForkPoolWorker-18] Task do_host_app.tasks.host_tasks.host_enable_m2m[ab586360-dff1-4b2b-86b5-bb8186f4a986] raised unexpected: {""code"": ""DO_M2MEXCEPTION"", ""message"": ""[M2M]Fail to set m2m switch on host:<Host FQDN> to True"", ""params"": [], ""context"": {}, ""task"": null}"
2022-12-02-11:41:31 microservice.do-host "Traceback (most recent call last):"
2022-12-02-11:41:31 microservice.do-host "  File ""/home/app/do_host_app/tasks/host_tasks.py"", line 583, in host_enable_m2m"
2022-12-02-11:41:31 microservice.do-host "    operator.apply_vxm_cert_and_enable_m2m()"
2022-12-02-11:41:31 microservice.do-host "  File ""/home/app/do_host_app/rest/m2m_operations.py"", line 870, in apply_vxm_cert_and_enable_m2m"
2022-12-02-11:41:31 microservice.do-host "    execute()"
2022-12-02-11:41:31 microservice.do-host "  File ""/usr/local/venv/lib/python3.6/site-packages/do_common/distributed_lock.py"", line 91, in call"
2022-12-02-11:41:31 microservice.do-host "    raise e"
2022-12-02-11:41:31 microservice.do-host "  File ""/usr/local/venv/lib/python3.6/site-packages/do_common/distributed_lock.py"", line 88, in call"
2022-12-02-11:41:31 microservice.do-host "    ret = func(*args, **kwargs)"
2022-12-02-11:41:31 microservice.do-host "  File ""/home/app/do_host_app/rest/m2m_operations.py"", line 860, in execute"
2022-12-02-11:41:31 microservice.do-host "    self.linzhi_operator.set_m2m_status(True)"
2022-12-02-11:41:31 microservice.do-host "  File ""/home/app/do_host_app/rest/m2m_operations.py"", line 395, in set_m2m_status"
2022-12-02-11:41:31 microservice.do-host "    f""[M2M]Fail to set m2m switch on host:{self.host} to {enabled}"")"
2022-12-02-11:41:31 microservice.do-host "do_host_app.rest.m2m_operations.M2MException: [M2M]Fail to set m2m switch on host:<Host FQDN>to True"

2022-12-02-11:41:31 microservice.do-host "do_common.exception.task_exception.DOTaskExecutionError: {""code"": ""DO_M2MEXCEPTION"", ""message"": ""[M2M]Fail to set m2m switch on <Host FQDN> to True"", ""params"": [], ""context"": {}, ""task"": null}"
2022-12-02-11:41:31 microservice.do-host ""
2022-12-02-11:41:31 microservice.do-host "2022-12-02 11:41:31,928 [ERROR] <Dummy-26:139938204178248> async_tasks.py get() (291): Task execution error: {'code': 'DO_M2MEXCEPTION', 'message': '[M2M]Fail to set m2m switch on <Host FQDN> to True', 'params': []}"
or 
2022-12-02-14:44:33 microservice.do-host "[2022-12-02 14:44:33,132: WARNING/ForkPoolWorker-22] Occur SSLError when sending linzhi request with read_type:VxmCertReadType.NORMAL, the error is HTTPSConnectionPool(host='<Host FQDN>', port=9090): Max retries exceeded with url: /rest/ps/private/v1/misc/certservice/mtls (Caused by SSLError(SSLError(1, '[SSL: TLSV1_ALERT_UNKNOWN_CA] tlsv1 alert unknown ca (_ssl.c:852)'),)), retry next in [<VxmCertReadType.NORMAL: 'normal'>]"
2022-12-02-14:44:33 microservice.do-host "[2022-12-02 14:44:33,132: WARNING/ForkPoolWorker-22] [M2M]change m2m status error:Failed to send Linzhi request due to SSLError, Please check if vxm cert:/vxm_cert/server.api.gateway.crt and /vxm_cert/server.key are correct, will retry automatically"

Ursache

Ein fehlerhaftes VxRail Manager-Zertifikat oder eine ca.cnf-Datei hat einen unerwarteten Eintrag, der zum SSL-Handshake-Fehler zwischen dem VxRail Manager und dem Hostplattformservice (Linzhi) führt.

Lösung

  1. Folgen Sie VxRail: Anforderungen für das VxRail Manager-SSL-Zertifikat in einem mTLS-fähigen Cluster. Prüfen Sie, ob das VxRail Manager-Zertifikat die Anforderungen erfüllt.
  2. Erstellen Sie ein Backup der aktuellen ca.cnf-Datei:
    cp /etc/vmware-marvin/ssl/ca.cnf /etc/vmware-marvin/ssl/ca.cnf.bak
  3. Ändern Sie die Datei /etc/vmware-marvin/ssl/ca.cnf, um die Zeile "keyUsage" zu entfernen:
    [ v3_req ]
    subjectAltName = @alt_names
    basicConstraints = CA:false
    keyUsage = digitalSignature, keyEncipherment, dataEncipherment <--- need to remove this line
    extendedKeyUsage = serverAuth, clientAuth
  4. Stellen Sie sicher, dass "alt_names" in cn.cnf enthält die korrekten Einträge für VxRail Manager-IP/FQDN.
     

Weitere Informationen

Das Problem tritt auf Codeversion 7.0.350 auf.

Betroffene Produkte

VxRail
Artikeleigenschaften
Artikelnummer: 000206115
Artikeltyp: Solution
Zuletzt geändert: 23 Juni 2026
Version:  3
Antworten auf Ihre Fragen erhalten Sie von anderen Dell NutzerInnen
Support Services
Prüfen Sie, ob Ihr Gerät durch Support Services abgedeckt ist.