Data Domain:DDOS 7.x 升级后无法访问 Enterprise System Manager UI
Summary: 升级到 DDOS 7.x 后,无法访问 Data Domain Enterprise Manager (DDEM) / System Manager 图形用户界面 (GUI)
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
升级到 DDOS 7.x 后,无法访问 Data Domain Enterprise Manager (DDEM) / System Manager 图形用户界面 (GUI)。 它将报告 DDSM 服务不可用。
em.info 文件中将报告以下错误
em.info 文件中将报告以下错误
#log view debug/sm/em.info 12 Apr 2021 20:21:40,536 INFO [main] SMS is running in secure (HTTPS) mode. 12 Apr 2021 20:21:40,817 INFO [main] *** Creating mutual auth connection manager, max connections: 45, max connections per host: 2 12 Apr 2021 20:21:40,839 INFO [main] *** Creating no mutual auth connection manager, max connections: 1, max connections per host: 1 12 Apr 2021 20:21:40,839 INFO [main] *** Creating Http Client with connectTimeout: 30000, socketTimeout: 120000, connectionManagerTimeout: 30000 12 Apr 2021 20:21:40,916 INFO [main] *** Creating Http Client with connectTimeout: 30000, socketTimeout: 120000, connectionManagerTimeout: 30000 12 Apr 2021 20:21:41,217 INFO [main] Re-initializing the certificates between the client and the server 12 Apr 2021 20:21:41,217 INFO [main] Reloading the certificate stores for the system 12 Apr 2021 20:21:41,228 INFO [main] Finished reloading the certificate stores 12 Apr 2021 20:21:41,229 ERROR [main] Exception during command execution: javax.net.ssl.SSLException - Error creating premaster secret. , will retry, Attempt# 1 12 Apr 2021 20:21:41,380 INFO [main] Re-initializing the certificates between the client and the server 12 Apr 2021 20:21:41,381 INFO [main] Reloading the certificate stores for the system 12 Apr 2021 20:21:41,397 INFO [main] Finished reloading the certificate stores
Cause
自 DDOS 6.0 起,GUI 默认使用的证书的密钥长度为 2048。而在 DDOS 5.x 版本中,密钥强度为 1024 位。密钥长度增加到 2048。
作为增强安全强化的一部分,DDOS 7.x 强制实施此密钥强度
作为增强安全强化的一部分,DDOS 7.x 强制实施此密钥强度
Resolution
适用于使用默认自签名证书的系统
步骤 1:
- 如果您通过检查确定我们遇到了此知识库文章中的问题 em.info,请按照此知识库文章中的步骤重新生成新的 CA 证书:
- Data Domain:由于 https 证书过期,Web UI 无法访问
步骤 1:
- 以“sysadmin”或等效用户身份通过 CLI 登录到 DD,然后转到“SE privilege mode”
提醒:SE 命令在 DDOS 版本 7.7.5.25、7.10.1.15、7.13.0.15、6.2.1.110 及更高版本中已弃用,并且只能由戴尔员工访问
- 删除使用的当前证书
# adminaccess certificate delete imported-host application https
- 现在,按照本知识库文章中的步骤生成新的自签名 CA 证书
- Data Domain:由于 https 证书过期,Web UI 无法访问
- 要导入新的外部签名证书,请使用以下知识库文章:
- Data Domain:如何生成证书签名请求并使用外部签名的证书
Affected Products
Data DomainArticle Properties
Article Number: 000185217
Article Type: Solution
Last Modified: 04 Sept 2025
Version: 9
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.