NetWorker: O NMC não consegue verificar certificados após a alteração de versão do servidor NMC.

Summary: O software NetWorker Management Console (NMC) é atualizado em um host Linux. Depois de executar o upgrade. O serviço GST do NMC não está sendo inicializado e está relatando erros de validação de certificado. ...

Acest articol se aplică pentru Acest articol nu se aplică pentru Acest articol nu este legat de un produs specific. Acest articol nu acoperă toate versiunile de produs existente.

Symptoms

  • Um pacote de servidor NetWorker Management Console (NMC) do Linux foi atualizado.
  • A coluna nmc_config script da opção Use Existing (ue), foi especificado.
  • A coluna nmc_config O script relata o seguinte erro:
[root@NMCxxx ~]# /opt/lgtonmc/bin/nmc_config
The embedded web server inside the NMC server must run as a non-root user.
EMC recommends that you specify a user that has limited privileges and
file access permissions. Default user name used is 'nsrnmc'.

Do you want to create new(cn) certificate or use existing(ue) certificate [ue]? ue

Do you want to use "/nsr/certs/certxxx.pem" certificate file & "/nsr/certs/privatekey.key" key file [y]? y

ERROR: Key file "/nsr/certs/privatekey.key" does not correspond to certificate file "/nsr/certs/certxxx.pem".
  • A coluna /opt/lgtonmc/logs/Install.log mostra abaixo
Validation Failed, Configuration can not retained during upgrade.
Please run /opt/lgtonmc/bin/nmc_config after rpm installation.
Changing the ownership of /nsr/nmc/nmcdb to nsrnmc
** running: /opt/lgtonmc/bin/gstconfig -r
Reading private key from /nsr/certs/privatekey.key
Reading certificate from /nsr/certs/certxxx.pem
187258:gstconfig: Error while verifying certificate, error:04091077:rsa routines:INT_RSA_VERIFY:wrong signature length .
Error in comssl_verify_cert_and_privkeyReading private key from /nsr/certs/privatekey.key
187257:gstconfig: Could not read the private key.
187258:gstconfig: Error while verifying certificate, error:0906D06C:PEM routines:PEM_read_bio:no start line .
** running: /opt/lgtonmc/bin/gstconfig -c

Cause

A opção Use Existing não pôde verificar a assinatura ao ler a chave privada; A causa não foi determinada.

Resolution

  1. Abra um shell raiz no servidor NMC e execute o comando /opt/lgtonmc/bin/nmc_config Script; no entanto, especifique Create New (cn):
[root@NMCxxx certs]# /opt/lgtonmc/bin/nmc_config
NOTE
====
Install has detected the configuration file of a previous lgtonmc
package. Install will attempt to read the configuration parameters
in this file and present them as default values where appropriate.
Please modify any value that is incorrect or needs to be changed.
The embedded web server inside the NMC server must run as a non-root user.
EMC recommends that you specify a user that has limited privileges and
file access permissions. Default user name used is 'nsrnmc'.

Do you want to create new(cn) certificate or use existing(ue) certificate [ue]? cn
Creating new certificate for https configuration.

Specify the directory to use for the LGTOnmc database [/nsr/nmc/nmcdb]:
A database already exists in /nsr/nmc/nmcdb, do you want to retain this database [y]?
Specify the host name of the NetWorker Authentication Service host [Authxxx.FQDN]:
Start the NMC server daemons at end of the configuration [y]? SEE BELOW POINT BEFORE CHOOSING Y/N
Creating the installation log in /opt/lgtonmc/logs/install.log.
Performing initialization. Please wait...

The installation completed successfully.
  • Antes de iniciar os serviços do GST, considere o seguinte:
    • Se você estava usando anteriormente os certificados autoassinados padrão criados por nmc_config. Você pode usar o recém-gerado. Nesse caso, digite y para iniciar o serviço GST do servidor do NMC após a conclusão do script. Nenhuma etapa adicional é necessária.
    • Se você substituiu anteriormente os certificados autoassinados por certificados assinados por certificados assinados por CA, digite n e prossiga com as etapas a seguir.
  1. Use um editor de texto para abrir o httpd.conf para especificar os certificados usados anteriormente: vi /opt/lgtonmc/apache/conf/httpd.conf
    1. Pesquise por SSLCertificatefile e especifique o caminho completo para o arquivo de certificado usado anteriormente.
    2. Pesquise por SSLCertificateKeyfile e especifique o caminho completo para o arquivo de chave usado anteriormente.
    3. Salve o arquivo.
  2. Inicie os serviços do NetWorker e do GST: systemctl start gst
  3. Monitore o /opt/lgtonmc/logs/gstd.raw para erros.

NetWorker: Como usar nsr_render_log para processar arquivos de log .raw

Additional Information

Nota: Se o problema persistir após a reversão para a chave e o certificado assinados pela CA anteriores. Valide o arquivo usado ou consulte a seguinte arquitetura para importar um novo certificado e uma nova chave: NetWorker: Como importar ou substituir certificados assinados pela autoridade de certificação do NMC

Produse afectate

NetWorker, NetWorker Management Console

Produse

NetWorker Family
Proprietăți articol
Article Number: 000200619
Article Type: Solution
Ultima modificare: 14 mai 2026
Version:  6
Găsiți răspunsuri la întrebările dvs. de la alți utilizatori Dell
Servicii de asistență
Verificați dacă dispozitivul dvs. este acoperit de serviciile de asistență.