Dell NativeEdge:对 NativeEdge Orchestrator 部署期间的证书问题进行故障处理
Summary: 本文旨在帮助对在 NativeEdge Orchestrator 部署期间报告错误0x016030001的证书问题进行故障处理。 0x016030001是当使用 docker 与存储库通信失败时 NativeEdge Orchestrator 安装程序报告的事件代码。
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
由于证书问题,部署无法启动。
情形:
Error response from daemon: Get "https://repository.nativeedge.local/v2/": x509: certificate relies on legacy Common Name field, use SANs instead Login failed. Please check the image registry credentials. Error code: 0x016030001
Error response from daemon: Get "https://repository.nativeedge.local/v2/": Get "https://<ip>/service/token?account=admin&client_id=docker&offline_token=true&service=harbor-registry": tls: failed to verify certificate: x509: certificate signed by unknown authority Login failed. Please check the image registry credentials. Error code: 0x016030001
Error response from daemon: Get "https://repository.nativeedge.local/v2/": Get "https://<ip>/service/tokenaccount=admin&client_id=docker&offline_token=true&service=harbor-registry": tls: failed to verify certificate: x509: cannot validate certificate for <ip> because it doesn't contain any IP SANs Login failed. Please check the image registry credentials. Error code: 0x016030001
Cause
在上述情景中,原因如下:
- 存储库上配置的 SSL 证书没有在证书中设置任何主题备用名称 (SAN) 字段,只有传统的通用名称字段。
- 查看此错误时发现,存储库在设置过程中的 IP 地址配置错误,因此当 docker 尝试将 NativeEdge 安装程序上传到存储库时,它查询了不正确的存储库。
- 存储库上配置的 SSL 证书未在其 SAN x509 扩展中配置 IP 地址
Resolution
在上述情景中,解决方案如下:
- 更正存储库中的证书以包括主题备用名称 (SAN) 信息
- 正确地重新配置存储库,使其使用正确的地址进行通信
- 更正存储库中的证书以包括 SAN IP 信息
Affected Products
Dell Distributed Private Cloud, NativeEdgeArticle Properties
Article Number: 000217449
Article Type: Solution
Last Modified: 22 Jan 2025
Version: 2
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.