Uploaded image for project: 'Couchbase Server'
  1. Couchbase Server
  2. MB-50046

TLS:Unable to load travel-sample: error: tls_alert certificate unknown

    XMLWordPrintable

Details

    • Bug
    • Resolution: Duplicate
    • Critical
    • None
    • 6.6.5
    • ns_server
    • None
    • Triaged
    • 1
    • Unknown

    Description

      Build: 6.6.4-9949

      • Cluster with 2 node : kv,index,search and index,search
      • enable tls

        /opt/couchbase/bin/couchbase-cli node-to-node-encryption -c localhost:8091 -u Administrator -p password --enable --no-ssl-verify
         curl -XPOST localhost:8091/internalSettings -d 'canEnableStrictEncryption=true' -u Administrator:password
        curl -XPOST localhost:8091/settings/security -d 'clusterEncryptionLevel=strict' -u Administrator:password
        

      • Try loading travel-sample from UI
      • UI says "Task added successfully" but travel-sample not loaded.

      Seeing below in the logs:

      =========================ERROR REPORT=========================
      {mochiweb_socket_server,291,{acceptor_error,{error,accept_failed}}}
      [error_logger:info,2021-12-10T13:04:38.388-08:00,ns_1@172.23.97.211:error_logger<0.32.0>:ale_error_logger_handler:do_log:203]
      =========================INFO REPORT=========================
                            "TLS"
                            32
                            "server"
                            58
                            32
                            73
                            110
                            32
                            115
                            116
                            97
                            116
                            101
                            32
                            "abbreviated"
                            32
                            "received CLIENT ALERT: Fatal - Certificate Unknown"
                            10
       
      [error_logger:error,2021-12-10T13:04:38.389-08:00,ns_1@172.23.97.211:error_logger<0.32.0>:ale_error_logger_handler:do_log:203]
      =========================ERROR REPORT=========================
               application: mochiweb
                            "SSL handshake failed"
                            "{error,{tls_alert,\"certificate unknown\"}}"
       
      [error_logger:error,2021-12-10T13:04:38.389-08:00,ns_1@172.23.97.211:error_logger<0.32.0>:ale_error_logger_handler:do_log:203]
      =========================ERROR REPORT=========================
               application: mochiweb
                            "Accept failed error"
                            "{error,{tls_alert,\"certificate unknown\"}}"
       
      [error_logger:error,2021-12-10T13:04:38.389-08:00,ns_1@172.23.97.211:error_logger<0.32.0>:ale_error_logger_handler:do_log:203]
      =========================CRASH REPORT=========================
        crasher:
          initial call: mochiweb_acceptor:init/3
          pid: <0.11111.6>
          registered_name: []
          exception exit: {error,accept_failed}
            in function  mochiweb_acceptor:init/3 (/home/couchbase/jenkins/workspace/couchbase-server-unix/couchdb/src/mochiweb/mochiweb_acceptor.erl, line 33)
          ancestors: [menelaus_web_ssl_ipv4,<0.22636.5>,<0.214.0>,
                        ns_ssl_services_sup,ns_server_nodes_sup,<0.204.0>,
                        ns_server_cluster_sup,root_sup,<0.117.0>]
          message_queue_len: 0
          messages: []
      
      

      Logs:

      https://cb-jira.s3.us-east-2.amazonaws.com/logs/test/collectinfo-2021-12-10T210334-ns_1%40172.23.97.211.zip
      https://cb-jira.s3.us-east-2.amazonaws.com/logs/test/collectinfo-2021-12-10T210334-ns_1%40172.23.97.212.zip

      Attachments

        Issue Links

          No reviews matched the request. Check your Options in the drop-down menu of this sections header.

          Activity

            People

              girish.benakappa Girish Benakappa
              girish.benakappa Girish Benakappa
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Gerrit Reviews

                  There are no open Gerrit changes

                  PagerDuty