NetWorker: NMC nie może zweryfikować certyfikatów po zmianie wersji serwera NMC.
Summary: Oprogramowanie konsoli NetWorker Management Console (NMC) zostanie zaktualizowane na hoście Linux. Po przeprowadzeniu uaktualnienia. Usługa GST NMC nie uruchamia się i nie zgłasza błędów weryfikacji certyfikatu. ...
Acest articol se aplică pentru
Acest articol nu se aplică pentru
Acest articol nu este legat de un produs specific.
Acest articol nu acoperă toate versiunile de produs existente.
Symptoms
- Pakiet serwera Linux NetWorker Management Console (NMC) został uaktualniony.
- Pakiet
nmc_configskrypt opcji Użyj istniejącego (ue) sprecyzowano. - Pakiet
nmc_configSkrypt zgłasza następujący błąd:
[root@NMCxxx ~]# /opt/lgtonmc/bin/nmc_config
The embedded web server inside the NMC server must run as a non-root user.
EMC recommends that you specify a user that has limited privileges and
file access permissions. Default user name used is 'nsrnmc'.
Do you want to create new(cn) certificate or use existing(ue) certificate [ue]? ue
Do you want to use "/nsr/certs/certxxx.pem" certificate file & "/nsr/certs/privatekey.key" key file [y]? y
ERROR: Key file "/nsr/certs/privatekey.key" does not correspond to certificate file "/nsr/certs/certxxx.pem".
- Pakiet
/opt/lgtonmc/logs/Install.logpokazuje poniżej
Validation Failed, Configuration can not retained during upgrade.
Please run /opt/lgtonmc/bin/nmc_config after rpm installation.
Changing the ownership of /nsr/nmc/nmcdb to nsrnmc
** running: /opt/lgtonmc/bin/gstconfig -r
Reading private key from /nsr/certs/privatekey.key
Reading certificate from /nsr/certs/certxxx.pem
187258:gstconfig: Error while verifying certificate, error:04091077:rsa routines:INT_RSA_VERIFY:wrong signature length .
Error in comssl_verify_cert_and_privkeyReading private key from /nsr/certs/privatekey.key
187257:gstconfig: Could not read the private key.
187258:gstconfig: Error while verifying certificate, error:0906D06C:PEM routines:PEM_read_bio:no start line .
** running: /opt/lgtonmc/bin/gstconfig -cCause
Opcja Użyj istniejącego nie była w stanie zweryfikować podpisu podczas odczytywania klucza prywatnego; Przyczyna była nieustalona.
Resolution
- Otwórz powłokę główną na serwerze NMC i uruchom polecenie
/opt/lgtonmc/bin/nmc_configSkrypt; jednak określ Utwórz nowy (cn):
[root@NMCxxx certs]# /opt/lgtonmc/bin/nmc_config
NOTE
====
Install has detected the configuration file of a previous lgtonmc
package. Install will attempt to read the configuration parameters
in this file and present them as default values where appropriate.
Please modify any value that is incorrect or needs to be changed.
The embedded web server inside the NMC server must run as a non-root user.
EMC recommends that you specify a user that has limited privileges and
file access permissions. Default user name used is 'nsrnmc'.
Do you want to create new(cn) certificate or use existing(ue) certificate [ue]? cn
Creating new certificate for https configuration.
Specify the directory to use for the LGTOnmc database [/nsr/nmc/nmcdb]:
A database already exists in /nsr/nmc/nmcdb, do you want to retain this database [y]?
Specify the host name of the NetWorker Authentication Service host [Authxxx.FQDN]:
Start the NMC server daemons at end of the configuration [y]? SEE BELOW POINT BEFORE CHOOSING Y/N
Creating the installation log in /opt/lgtonmc/logs/install.log.
Performing initialization. Please wait...
The installation completed successfully.
- Przed uruchomieniem usług GST należy wziąć pod uwagę następujące kwestie:
-
- Jeśli wcześniej używano domyślnych certyfikatów z podpisem własnym utworzonych przez
nmc_config. Możesz użyć nowo wygenerowanego. W takim przypadku wprowadźy, aby uruchomić usługę GST serwera NMC po zakończeniu skryptu. Nie są wymagane żadne dalsze czynności. - Jeśli certyfikaty z podpisem własnym zostały wcześniej zastąpione certyfikatami podpisanymi przez urząd certyfikacji, wprowadź
ni wykonaj następujące czynności.
- Jeśli wcześniej używano domyślnych certyfikatów z podpisem własnym utworzonych przez
- Użyj edytora tekstu, aby otworzyć
httpd.conf, aby określić poprzednio używane certyfikaty:vi /opt/lgtonmc/apache/conf/httpd.conf- Wyszukaj
SSLCertificatefilei określ pełną ścieżkę do poprzednio używanego pliku certyfikatu. - Wyszukaj
SSLCertificateKeyfilei określ pełną ścieżkę do poprzednio używanego pliku klucza. - Zapisz plik.
- Wyszukaj
- Uruchom usługi NetWorker i GST:
systemctl start gst - Monitoruj
/opt/lgtonmc/logs/gstd.rawza błędy.
NetWorker: Jak używać nsr_render_log do renderowania plików dziennika .raw
Additional Information
UWAGA: Jeśli problem nie ustąpi po przywróceniu poprzedniego certyfikatu i klucza podpisanego przez instytucję certyfikującą. Sprawdź poprawność używanego pliku lub zapoznaj się z następującym artykułem dotyczącym importowania nowego certyfikatu i klucza: NetWorker: Jak zaimportować lub zastąpić certyfikaty podpisane przez urząd certyfikacji dla NMC
Produse afectate
NetWorker, NetWorker Management ConsoleProduse
NetWorker FamilyProprietăți articol
Article Number: 000200619
Article Type: Solution
Ultima modificare: 14 mai 2026
Version: 6
Găsiți răspunsuri la întrebările dvs. de la alți utilizatori Dell
Servicii de asistență
Verificați dacă dispozitivul dvs. este acoperit de serviciile de asistență.