Integração do Avamar e do Data Domain: Não é possível sincronizar certificados com a segurança da sessão ativada

Summary: Quando a segurança da sessão está habilitada no Avamar, os certificados devem sincronizar entre o Avamar e o Data Domain. Isso exige que o protocolo SCP seja habilitado no Data Domain.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

Os backups podem falhar com os seguintes erros:
DDR result code: 5049, desc: file not found
DDR result code: 5341, desc: SSL library error "failed to import host or ca certificate automatically"
DDR result code: 5008, desc: invalid argument
Ao seguir o artigo da Dell 197106, Avamar e Integração do Data Domain: DD mostrando vermelho na AUI do Avamar e ou no caminho de resolução da interface do usuário, os certificados não são gerados.

Ao verificar os registros do MCS, há uma exceção relacionada ao protocolo SCP.
09/29-16:29:13.00727 [RMI TCP Connection(27)-192.x.x.x#965] com.avamar.mc.datadomain.DdrCache.firsttimeToAddEx
FINE: Importing host certificate and ca certificates...
09/29-16:29:13.00743 [RMI TCP Connection(27)-192.x.x.x#965] com.avamar.mc.datadomain.DdrSsh.executeDdrCommand
FINE: Executing ddr command. host: idpa-lab.dell.com cmd: adminaccess certificate cert-signing-request show ...
09/29-16:29:14.00095 [RMI TCP Connection(27)-192.x.x.x#965] com.avamar.mc.kc.PrefsCertRsa.
FINE: RSA certificate:
09/29-16:29:14.00095 [RMI TCP Connection(27)-192.x.x.x#965] com.avamar.mc.kc.PrefsCertRsa.
FINE: Message digest algorithm: sha512
09/29-16:29:14.00095 [RMI TCP Connection(27)-192.x.x.x#965] com.avamar.mc.datadomain.PrefsDdrCert.
INFO: DD RSA certificate:
09/29-16:29:14.00095 [RMI TCP Connection(27)-192.x.x.x#965] com.avamar.mc.datadomain.PrefsDdrCert.
INFO: Number bits(key strength): 3072bit
09/29-16:29:14.00095 [RMI TCP Connection(27)-192.x.x.x#965] com.avamar.mc.datadomain.PrefsDdrCert.
INFO: Message digest algorithm: sha512
09/29-16:29:14.00137 [RMI TCP Connection(27)-192.x.x.x#965] com.avamar.mc.datadomain.DdrSsh.executeDdrCommand
FINE: Executing ddr command. host: idpa-lab.dell.com cmd: adminaccess certificate cert-signing-request generate  key-strength 3072bit country 'US' state 'California' city 'Irvine' org-name 'EMC Corp' org-unit 'BRS Division'...
09/29-16:29:14.00721 [RMI TCP Connection(27)-192.x.x.x#965] com.avamar.mc.datadomain.DdrSsh.copyFile
FINE: Copying file from host: idpa-lab.dell.com...
09/29-16:29:15.00619 [RMI TCP Connection(27)-192.x.x.x#965] com.avamar.mc.datadomain.DdrSsh.copyFile
WARNING: Failed to copy file from host: idpa-lab.dell.com.
09/29-16:29:15.00619 [RMI TCP Connection(27)-192.x.x.x#965] com.avamar.mc.util.MCException.logException
WARNING: com.maverick.ssh.SshException: java.io.IOException
  at com.maverick.scp.ScpClientIO.get(ScpClientIO.java:151)
  at com.maverick.scp.ScpClientIO.get(ScpClientIO.java:124)
  at com.avamar.mc.datadomain.DdrSsh.copyFile(DdrSsh.java:940)
  at com.avamar.mc.datadomain.DdrSsh.copyFileEx(DdrSsh.java:961)
  at com.avamar.mc.datadomain.DdrSshCertificateCmd.getcertificateSigningRequest(DdrSshCertificateCmd.java:200)
  at com.avamar.mc.datadomain.DataDomainService.generateAndImportDdrHostCert(DataDomainService.java:5520)
  at com.avamar.mc.datadomain.DataDomainService.firsttimeToAdd(DataDomainService.java:5183)
  at com.avamar.mc.datadomain.DataDomainService.firsttimeToAdd(DataDomainService.java:6041)
  at com.avamar.mc.datadomain.DdrCache.firsttimeToAdd(DdrCache.java:1599)
  at com.avamar.mc.datadomain.DdrCache.firsttimeToAddEx(DdrCache.java:1645)
  at com.avamar.mc.datadomain.DdrCache.ConfigCerts(DdrCache.java:1454)
  at com.avamar.mc.datadomain.DdrCache.checkAndConfigCerts(DdrCache.java:1251)
  at com.avamar.mc.datadomain.DdrCache.update(DdrCache.java:402)
  at com.avamar.mc.datadomain.DdrCache.update(DdrCache.java:676)
  at com.avamar.mc.datadomain.DataDomainService.rewriteDdrCloudInfo(DataDomainService.java:6457)
  at com.avamar.mc.datadomain.DataDomainService.disableCloudTier(DataDomainService.java:6486)
  at com.avamar.mc.datadomain.DataDomainService._updateDdr(DataDomainService.java:1271)
  at com.avamar.mc.datadomain.DataDomainService.updateDdr(DataDomainService.java:1036)
  at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
  at sun.reflect.NativeMethodAccessorImpl.invoke(Unknown Source)
  at sun.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)
  at java.lang.reflect.Method.invoke(Unknown Source)
  at org.springframework.aop.support.AopUtils.invokeJoinpointUsingReflection(AopUtils.java:318)
  at org.springframework.aop.framework.ReflectiveMethodInvocation.invokeJoinpoint(ReflectiveMethodInvocation.java:183)
  at org.springframework.aop.support.AopUtils.invokeJoinpointUsingReflection(AopUtils.java:318)
  at org.springframework.aop.framework.ReflectiveMethodInvocation.invokeJoinpoint(ReflectiveMethodInvocation.java:183)
  at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:150)
  at org.springframework.security.access.intercept.aopalliance.MethodSecurityInterceptor.invoke(MethodSecurityInterceptor.java:61)
  at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:172)
  at org.springframework.aop.framework.JdkDynamicAopProxy.invoke(JdkDynamicAopProxy.java:202)
  at com.sun.proxy.$Proxy37.updateDdr(Unknown Source)
  at com.avamar.mc.datadomain.DataDomainServiceContext.updateDdr(DataDomainServiceContext.java:223)
  at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
  at sun.reflect.NativeMethodAccessorImpl.invoke(Unknown Source)
  at sun.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)
  at java.lang.reflect.Method.invoke(Unknown Source)
  at sun.rmi.server.UnicastServerRef.dispatch(Unknown Source)
  at sun.rmi.transport.Transport$1.run(Unknown Source)
  at sun.rmi.transport.Transport$1.run(Unknown Source)
  at java.security.AccessController.doPrivileged(Native Method)
  at sun.rmi.transport.Transport.serviceCall(Unknown Source)
  at sun.rmi.transport.tcp.TCPTransport.handleMessages(Unknown Source)
  at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0(Unknown Source)
  at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.lambda$run$0(Unknown Source)
  at java.security.AccessController.doPrivileged(Native Method)
  at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run(Unknown Source)
  at java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source)
  at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)
  at java.lang.Thread.run(Unknown Source)
Caused by: java.io.IOException: SCP unexpected cmd: Scp is disabled. Access denied.
  at com.maverick.scp.ScpClientIO$ScpEngineIO.readStreamFromRemote(ScpClientIO.java:305)
  at com.maverick.scp.ScpClientIO.get(ScpClientIO.java:148)
  at com.maverick.scp.ScpClientIO.get(ScpClientIO.java:124)
  at com.avamar.mc.datadomain.DdrSsh.copyFile(DdrSsh.java:940)
  at com.avamar.mc.datadomain.DdrSsh.copyFileEx(DdrSsh.java:961)
  at com.avamar.mc.datadomain.DdrSshCertificateCmd.getcertificateSigningRequest(DdrSshCertificateCmd.java:200)
  at com.avamar.mc.datadomain.DataDomainService.generateAndImportDdrHostCert(DataDomainService.java:5520)
  at com.avamar.mc.datadomain.DataDomainService.firsttimeToAdd(DataDomainService.java:5183)
  at com.avamar.mc.datadomain.DataDomainService.firsttimeToAdd(DataDomainService.java:6041)
  at com.avamar.mc.datadomain.DdrCache.firsttimeToAdd(DdrCache.java:1599)
  at com.avamar.mc.datadomain.DdrCache.firsttimeToAddEx(DdrCache.java:1645)
  at com.avamar.mc.datadomain.DdrCache.ConfigCerts(DdrCache.java:1454)
  at com.avamar.mc.datadomain.DdrCache.checkAndConfigCerts(DdrCache.java:1251)
  at com.avamar.mc.datadomain.DdrCache.update(DdrCache.java:402)
  at com.avamar.mc.datadomain.DdrCache.update(DdrCache.java:676)
  at com.avamar.mc.datadomain.DataDomainService.rewriteDdrCloudInfo(DataDomainService.java:6457)
  at com.avamar.mc.datadomain.DataDomainService.disableCloudTier(DataDomainService.java:6486)
  at com.avamar.mc.datadomain.DataDomainService._updateDdr(DataDomainService.java:1271)
  at com.avamar.mc.datadomain.DataDomainService.updateDdr(DataDomainService.java:1036)
  at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
  at sun.reflect.NativeMethodAccessorImpl.invoke(Unknown Source)
  at sun.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)
  at java.lang.reflect.Method.invoke(Unknown Source)
  at org.springframework.aop.support.AopUtils.invokeJoinpointUsingReflection(AopUtils.java:318)
  at org.springframework.aop.framework.ReflectiveMethodInvocation.invokeJoinpoint(ReflectiveMethodInvocation.java:183)
  at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:150)
  at org.springframework.security.access.intercept.aopalliance.MethodSecurityInterceptor.invoke(MethodSecurityInterceptor.java:61)
  at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:172)
  at org.springframework.aop.framework.JdkDynamicAopProxy.invoke(JdkDynamicAopProxy.java:202)
  at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:172)
  at org.springframework.aop.framework.JdkDynamicAopProxy.invoke(JdkDynamicAopProxy.java:202)
  at com.sun.proxy.$Proxy37.updateDdr(Unknown Source)
  at com.avamar.mc.datadomain.DataDomainServiceContext.updateDdr(DataDomainServiceContext.java:223)
  at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
  at sun.reflect.NativeMethodAccessorImpl.invoke(Unknown Source)
  at sun.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)
  at java.lang.reflect.Method.invoke(Unknown Source)
  at sun.rmi.server.UnicastServerRef.dispatch(Unknown Source)
  at sun.rmi.transport.Transport$1.run(Unknown Source)
  at sun.rmi.transport.Transport$1.run(Unknown Source)
  at java.security.AccessController.doPrivileged(Native Method)
  at sun.rmi.transport.Transport.serviceCall(Unknown Source)
  at sun.rmi.transport.tcp.TCPTransport.handleMessages(Unknown Source)
  at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0(Unknown Source)
  at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.lambda$run$0(Unknown Source)
  at java.security.AccessController.doPrivileged(Native Method)
  at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run(Unknown Source)
  at java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source)
  at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)
  at java.lang.Thread.run(Unknown Source)

Cause

Analise o registro mcserver:
/usr/local/avamar/var/mc/server_log/mcserver.log.0

Caused by: java.io.IOException: SCP unexpected cmd: Scp is disabled. Access denied.
Isso mostra que o protocolo SCP está desativado no Data Domain.

O fluxo de sincronização de certificados entre o Avamar e o Data Domain exige que o SCP seja habilitado como demonstrado abaixo:
  1. O Avamar executa um comando no Data Domain usando a chave pública do Data Domain para autenticação sem senha. O primeiro comando é gerar uma CSR (Certificate Signing Request, solicitação de assinatura de certificado) no Data Domain.
  2. Em seguida, o Avamar tenta copiar a CSR do Data Domain usando SCP, mas não consegue fazer isso quando o SCP está desativado no Data Domain.
  3. O Avamar usaria a CSR para assinar um certificado emitido para o Data Domain pela autoridade de certificação raiz do Avamar. No Data Domain, ele é chamado de certificado "imported-host ddboost".
Verificar a interface do usuário do Data Domain mostra que o SCP está desativado:
 
A interface do usuário do Data Domain mostra que o SCP está desativado
Figura 1: A interface do usuário do Data Domain mostra que o SCP está desativado
 

Resolution

Habilite o SCP na interface

Web do Data Domain Em Administration > Access > Services > Check SCP > Configure > Check Allow SCP.
 
Habilite o SCP na interface Web do Data Domain
Figura 2: Habilite o SCP na interface Web do Data Domain
 

Affected Products

Avamar
Article Properties
Article Number: 000218137
Article Type: Solution
Last Modified: 23 Nov 2023
Version:  4
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.