Avamar:與 Data Domain 整合的 Avamar 備份失敗,並顯示權杖加密失敗並傳回錯誤

Résumé: 與 Data Domain (DD) 整合的 Avamar 備份失敗。ddrmaing.log報告「令牌加密失敗並出錯」,ddfs.info 檔報告「此金鑰具有無效的金鑰魔術」。。

Cet article concerne Cet article ne concerne pas Cet article n’est associé à aucun produit spécifique. Toutes les versions du produit ne sont pas identifiées dans cet article.

Symptômes

與 Data Domain 整合的 Avamar 備份失敗。

檢閱 avtar 記錄指出錯誤是無效的權杖:

<snip>
2017-02-21 11:35:50 avtar Info <40058>: - Client connecting to the Avamar Server using authentication, client connecting to the Data Domain system using two-way authentication
2017-02-21 11:35:51 avtar Info <10540>: - Resolved Data Domain Server name "testdd.emc.com" to the IP address "10.241.170.73"
2017-02-21 11:35:51 avtar Info <41236>: - Connecting to Data Domain Server name "testdd.emc.com" with token:5ba93c9db0cff93f52b521d7420e43f6eda2784f
2017-02-21 11:35:51 avtar Error <41439>: Using invalid token:5ba93c9db0cff93f52b521d7420e43f6eda2784f
2017-02-21 11:35:51 avtar Error <10542>: Data Domain server "testdd.emc.com" open failed DDR result code: 4904, desc: Invalid API argument.
2017-02-21 11:35:51 avtar Error <10509>: Problem logging into the DDR server:'', only GSAN communication was enabled.
2017-02-21 11:35:51 avtar FATAL <17964>: Backup is incomplete because file "/ddr_files.xml" is missing
<snip> 
 

審查 /usr/local/avamar/var/ddrmaintlogs/ddrmaint.log Avamar 格線顯示權杖要求失敗:

<snip> 
Feb 21 11:35:23 av-un-ge06-adm0 ddrmaint.bin[47285]: Info: request-token:open_ddr:service handle:1 index:1 server:testdd.emc.com user:ddboost duration=1800 expires=2017-02-21 13:05:23
Feb 21 11:35:23 av-un-ge06-adm0 ddrmaint.bin[47285]: Error: request-token::body - Failed to get token. Use token=1:00. Error:5008 Reason:invalid argument
Feb 21 11:35:23 av-un-ge06-adm0 ddrmaint.bin[47285]: Error: <xxxx>Datadomain request token operation failed.  
<snip>
 

檢閱 /ddr/var/log/debug/ddfs.info 登入 Data Domain 顯示權杖加密因無效的金鑰魔術而失敗:

1.登入 Data Domain。

2.檢閱 ddfs.info 使用以下命令記錄:

log view debug/ddfs.info
<snip>
02/21 11:35:23.543 (tid 0x7f53bd82d990): ddboost-<testavamar.emc.com-59512>: testavamar.emc.com Local Time: Tue Feb 21 12:35:23 2017
02/21 11:35:23.553 (tid 0x7f53bd8078e0): nfsproc3_ost_get_token_3_svc: ost_build_token
02/21 11:35:23.553 (tid 0x7f53bd8078e0): ost_build_token()
02/21 11:35:23.553 (tid 0x7f53bd8078e0): ost_encrypt_string_with_key() This key has an invalid key magic 9df5c181
02/21 11:35:23.553 (tid 0x7f53bd8078e0): ost_build_token: Token encryption failed with error 5008  
02/21 11:35:23.553 (tid 0x7f53bd8078e0): nfsproc3_ost_get_token_3_svc: ost_build_token failed [DDErrno = 5008 (ost_encrypt_string_with_key() Invalid User Key, Cannot be used to decrypt string)]  
<snip>
 

如果無效的按鍵魔術訊息未出現在 ddfs.info 日誌,請停止引用本文。

Cause

必須刷新訪問令牌。

Résolution

1.從 Data Domain 上的 ddboost 帳戶撤銷權杖存取:

ddboost user revoke token-access <ddboost username>
 

2.在 Avamar UI 中,編輯 Data Domain 伺服器:

管理主控台伺服器 (MCS) UI:

a.在 Avamar Administrator 中,按一下伺服器啟動器按鈕。

伺服器視窗隨即顯示。

b. 按一下「伺服器管理」標籤。

c. 選取要編輯的 Data Domain。

d.d. 選取「動作編輯 > Data Domain 系統」。

「編輯 Data Domain 系統」對話方塊隨即出現。

e. 按一下「確定」。(不需要變更 DD 組態)

-- 或 --

Avamar 使用者介面 (AUI)

a.在 UI 中,選取系統 (在「系統管理」下)

b.b. 選取「Data Domain」。

c. 反白顯示要編輯的 Data Domain,然後按一下「編輯」。

d. 輸入 ddboost 使用者名稱和密碼 (兩次),然後按一下「驗證」。

應顯示下列訊息:已成功擷取 Data Domain 系統資訊 

如果登入資料正確,但收到下列項目:「無法取得 Data Domain 系統資訊」,請清除「使用憑證驗證進行 REST 通訊」,然後再試一次。

e. 按一下「下一步」、「下一步」和「完成」(不需要變更 DD 組態)

3.在 Data Domain 上重新啟動 DD Boost:

a.登入 Data Domain 上的 SSH 工作階段。

b.在 Data Domain CLI 中輸入下列命令:

ddboost disable
ddboost enable
 

4.執行測試備份,以確保這已解決無效的權杖問題。

Produits concernés

Avamar

Produits

Avamar, Data Domain
Propriétés de l’article
Numéro d’article: 000064950
Type d’article: Solution
Dernière modification: 19 May 2026
Version:  10
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.