Data Domain: 업그레이드 사전 검사에서 한 가지 차단 문제가 발견되었습니다. DD가 잘못된 버전(4)이 있는 CA를 신뢰합니다.
Samenvatting: 요약: 신뢰 체인의 오래된 인증서로 인해 DDOS 사전 검사가 실패합니다.
Dit artikel is van toepassing op
Dit artikel is niet van toepassing op
Dit artikel is niet gebonden aan een specifiek product.
Niet alle productversies worden in dit artikel vermeld.
Symptomen
증상: 업그레이드 사전 검사 중 오류: 현재 업그레이드 상태: DD OS 사전 검사에서 1개의 차단 문제가 발견되었습니다.
참고: 사전 검사 차단 문제는 /ddr/var/log/debug/platform/infra.log에 숫자 오류 코드와 함께 기록됩니다. 설명 메시지 없이 숫자 오류 코드(예: "error 34")가 발생한 경우 infra.log에서 자세한 오류 설명을 검토하십시오.
log view debug/platform/infra.log
"사전 검사" 또는 "차단" 항목을 검색하여 특정 문제를 식별하고 적절한 해결 문서와 일치시킵니다.
예:
sysadmin@dd9300# system upgrade status
Current Upgrade Status: DD OS precheck found 1 blocking issue(s)
Node Severity Issue Solution
---- -------- ------------------------------ --------
0 WARNING The default Local user passwords may
password-strength policy need to be modified to
will be updated after the comply with new policy.
upgrade.
0 CRITICAL DD trusts CA with incorrect Retry upgrade after
version (4). Regenerating the CA with
subject <systemhostname>
0 WARNING 1 precheck script(s) failed Please get more details in
to complete /ddr/var/log/debug/platform/in
fra.log
End time: 2023.06.21:12:47Oorzaak
신뢰 체인에 이전 인증서가 있습니다.
Oplossing
1. DD의 트러스트를 확인합니다.
- #adminaccess 트러스트 쇼
- 사전 검사의 오류에서 해당 호스트 이름을 찾습니다.
예:
sysadmin@dd9300# adminaccess trust show
Subject Type Valid From Valid Until Fingerprint
--------------------- ---------- ------------------------ ------------------------ -----------------------------------------------------------
<systemHostname> trusted-ca Thu Mar 24 10:33:03 2011 Sun Mar 16 10:33:03 2042 6F:22:F5:ED:F6:F2:29:82:2A:17:CE:6A:31:9D:2A:E2:60:2B:69:81
ddmc trusted-ca Sun Aug 24 10:22:40 2014 Wed Aug 16 10:22:40 2045 1B:CC:CC:44:04:ED:21:B9:69:D2:7C:96:31:C7:DE:BC:15:CC:04:AB
dpc trusted-ca Tue Nov 12 20:30:53 2019 Tue Nov 13 20:30:53 2029 A1:57:6A:10:B8:1E:88:72:01:88:61:F1:7D:D4:BC:22:4D:14:73:36
dd9300 trusted-ca Wed Oct 7 11:37:39 2020 Tue Oct 6 11:37:39 2026 54:A8:64:D1:FA:60:3C:81:42:89:D5:DD:78:D1:2B:74:AF:E6:F5:04
dd9300 trusted-ca Wed Oct 7 11:46:36 2020 Tue Oct 6 11:46:36 2026 DE:C2:6B:CC:BA:7A:EE:14:11:8E:76:CC:9A:23:A7:C4:8E:0D:6F:53
--------------------- ---------- ------------------------ ------------------------ -----------------------------------------------------------
2. 오류가 발생한 호스트 이름에 해당하는 DD 시스템을 고객이 계속 사용하고 있는지 고객에게 확인합니다. 시스템이 더 이상 사용되지 않는 것이 일반적입니다. DDMC 모니터링에도 사용할 수 있습니다. 명령이 복제에 사용되고 있는지 확인할 수도 있습니다.
- 구성 표시를 #replication
- DD가 mtree 복제를 위해 호스트 이름을 사용하고 있는지 확인합니다. 호스트 이름이 사용 중인 경우 인증서를 다시 생성해야 합니다.
- 이 예시에서는 DD가 더 이상 사용되지 않으며 복제 구성에서 찾을 수 없습니다.
예:
sysadmin@dd9300# replication show config
CTX Source Destination Connection Low-bw-optim Crepl-gc-bw-optim Encryption Enabled Max-repl-
Host and Port (Auth-mode) streams
--- ----------------------------------------------------- ----------------------------------------------------- --------------------------------- ------------ ----------------- ----------- ------- ---------
1 mtree://dd9300/data/col1/DD9300 mtree://9300/data/col1/DD9300 dd9300.xxxx.org (default) disabled disabled disabled yes 32
--- ----------------------------------------------------- ----------------------------------------------------- --------------------------------- ------------
3. 복제 또는 DDMC에 트러스트가 필요하지 않은 것으로 확인되면 이전 트러스트를 제거합니다.
- # adminaccess trust del <host hostname of other DD>
- 예: # adminaccess trust del host <systemHostname>
4. 사전 검사를 다시 실행하면 성공할 것입니다.
Getroffen producten
Data DomainArtikeleigenschappen
Artikelnummer: 000215203
Artikeltype: Solution
Laatst aangepast: 15 jul. 2026
Versie: 5
Vind antwoorden op uw vragen via andere Dell gebruikers
Support Services
Controleer of uw apparaat wordt gedekt door Support Services.