HPE Storage Users Group
https://3parug.com/

Quorum witness 5.0.2 SSL with domain certificates
https://3parug.com/viewtopic.php?f=27&t=3846
Page 1 of 1

Author:  profp62 [ Wed Oct 12, 2022 10:15 am ]
Post subject:  Quorum witness 5.0.2 SSL with domain certificates

Hi

I have problem with SSL configuration. Without SSL quorum is working, but the customer requires it.
I think, that qw-server cert is corect - the guide is clear - but there is no guide for qw-client.

No i have

showcert -service qw-client
Service Commonname Type Enddate Fingerprint
qw-client xxxxxxxxxxxxxxxxxx.cz csr -- finger
qw-client SRV-INTERNALCA-CA intca Nov 20 05:53:20 2029 GMT finger
qw-client* SRV-ROOTCA-CA rootca Nov 20 05:53:20 2029 GMT finger

showcert -service qw-server
Service Commonname Type Enddate Fingerprint
qw-server* SRV-ROOTCA-CA rootca Nov 20 05:53:20 2029 GMT finger

But

setrcopytarget witness check -ssl xxx.xxx.xxx.xxx
error: No route to Quorum Witness at xxx.xxx.xxx.xxx from any node.
If using ssl option, verify certificate configuration and consult Quorum Witness logs.

Network is ok, if i disable SSL on quorum server, it's working.

Have someone this config working ?

Thanks

Author:  david [ Sun Oct 16, 2022 3:26 pm ]
Post subject:  Re: Quorum witness 5.0.2 SSL with domain certificates

I have this set up done. Tried via cli, didn't work for some reason. Logged in to the gui on the primera and added the added the certs in there and it started working.

I didn't try at the time to figure out why. If I remember I will check my notes from when I did it. I have 2 more to install at work this month so will likely be trying it again.

Page 1 of 1 All times are UTC - 5 hours
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
http://www.phpbb.com/