Uploaded image for project: 'Couchbase Server'
  1. Couchbase Server
  2. MB-50244

[tools] --cluster-cert-info flag does not show cert info in ssl-manage subcommand

    XMLWordPrintable

Details

    • Bug
    • Resolution: Won't Fix
    • Major
    • 7.1.0
    • 7.1.0
    • tools
    • None
    • Triaged
    • Centos 64-bit
    • 1
    • Yes
    • Tools 2021 Dec

    Description

      Install Couchbase server 7.1.0-1985
      Create default bucket and get cacert information from couchbase-cli, failed to get cacert information

      [root@s44015 ~]# /opt/couchbase/bin/couchbase-cli ssl-manage --cluster-cert-info -c localhost -u Administrator -p password 
      The certificate being used by the cluster
      Node                  Expires                  Type      Subject
      172.23.121.224:8091   2049-12-31T23:59:59.000Z generated CN=Couchbase Server Node (172.23.121.224)
           Warning: Out-of-the-box certificates are self-signed. To further secure your system, you must create new X.509 certificates signed by a trusted CA.
      [root@s44015 ~]#
      
      

      Run with debug flag, got cacert information in output

      [root@s44015 ~]# /opt/couchbase/bin/couchbase-cli ssl-manage --cluster-cert-info -c localhost -u Administrator -p password  -d
      GET http://localhost:8091/pools 
      200, {'Cache-Control': 'no-cache,no-store,must-revalidate', 'Content-Length': '899', 'Content-Type': 'application/json', 'Date': 'Tue, 04 Jan 2022 16:09:44 GMT', 'Expires': 'Thu, 01 Jan 1970 00:00:00 GMT', 'Pragma': 'no-cache', 'Server': 'Couchbase Server', 'X-Content-Type-Options': 'nosniff', 'X-Frame-Options': 'DENY', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-XSS-Protection': '1; mode=block'}, b'{"isAdminCreds":true,"isROAdminCreds":false,"isEnterprise":true,"allowedServices":["kv","n1ql","index","fts","cbas","eventing","backup"],"isDeveloperPreview":false,"packageVariant":"linux","pools":[{"name":"default","uri":"/pools/default?uuid=9d970834a4173023f0d071c6b90b1787","streamingUri":"/poolsStreaming/default?uuid=9d970834a4173023f0d071c6b90b1787"}],"settings":{"maxParallelIndexers":"/settings/maxParallelIndexers?uuid=9d970834a4173023f0d071c6b90b1787","viewUpdateDaemon":"/settings/viewUpdateDaemon?uuid=9d970834a4173023f0d071c6b90b1787"},"uuid":"9d970834a4173023f0d071c6b90b1787","implementationVersion":"7.1.0-1985-enterprise","componentsVersion":{"stdlib":"3.16.1","sasl":"4.1","asn1":"5.0.17","ale":"0.0.0","crypto":"5.0.4","ssl":"10.5.3","chronicle":"0.0.1","public_key":"1.11.3","ns_server":"7.1.0-1985-enterprise","kernel":"8.1.3","lhttpc":"1.3.0","os_mon":"2.7.1","inets":"7.4.2"}}'
      GET http://localhost:8091/pools 
      200, {'Cache-Control': 'no-cache,no-store,must-revalidate', 'Content-Length': '899', 'Content-Type': 'application/json', 'Date': 'Tue, 04 Jan 2022 16:09:44 GMT', 'Expires': 'Thu, 01 Jan 1970 00:00:00 GMT', 'Pragma': 'no-cache', 'Server': 'Couchbase Server', 'X-Content-Type-Options': 'nosniff', 'X-Frame-Options': 'DENY', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-XSS-Protection': '1; mode=block'}, b'{"isAdminCreds":true,"isROAdminCreds":false,"isEnterprise":true,"allowedServices":["kv","n1ql","index","fts","cbas","eventing","backup"],"isDeveloperPreview":false,"packageVariant":"linux","pools":[{"name":"default","uri":"/pools/default?uuid=9d970834a4173023f0d071c6b90b1787","streamingUri":"/poolsStreaming/default?uuid=9d970834a4173023f0d071c6b90b1787"}],"settings":{"maxParallelIndexers":"/settings/maxParallelIndexers?uuid=9d970834a4173023f0d071c6b90b1787","viewUpdateDaemon":"/settings/viewUpdateDaemon?uuid=9d970834a4173023f0d071c6b90b1787"},"uuid":"9d970834a4173023f0d071c6b90b1787","implementationVersion":"7.1.0-1985-enterprise","componentsVersion":{"stdlib":"3.16.1","sasl":"4.1","asn1":"5.0.17","ale":"0.0.0","crypto":"5.0.4","ssl":"10.5.3","chronicle":"0.0.1","public_key":"1.11.3","ns_server":"7.1.0-1985-enterprise","kernel":"8.1.3","lhttpc":"1.3.0","os_mon":"2.7.1","inets":"7.4.2"}}'
      GET http://localhost:8091/pools/default/certificates 
      200, {'Cache-Control': 'no-cache,no-store,must-revalidate', 'Content-Length': '1560', 'Content-Type': 'application/json', 'Date': 'Tue, 04 Jan 2022 16:09:44 GMT', 'Expires': 'Thu, 01 Jan 1970 00:00:00 GMT', 'Pragma': 'no-cache', 'Server': 'Couchbase Server', 'X-Content-Type-Options': 'nosniff', 'X-Frame-Options': 'DENY', 'X-Permitted-Cross-Domain-Policies': 'none', 'X-XSS-Protection': '1; mode=block'}, b'[{"node":"172.23.121.224:8091","warnings":[{"name":"self_signed","message":"Out-of-the-box certificates are self-signed. To further secure your system, you must create new X.509 certificates signed by a trusted CA.","severity":2,"severityName":"minimal"}],"subject":"CN=Couchbase Server Node (172.23.121.224)","expires":"2049-12-31T23:59:59.000Z","type":"generated","pem":"-----BEGIN CERTIFICATE-----\\nMIIDHTCCAgWgAwIBAgIIFscFgEQ0+bkwDQYJKoZIhvcNAQELBQAwJDEiMCAGA1UE\\nAxMZQ291Y2hiYXNlIFNlcnZlciA3N2ZiMjg2MjAeFw0xMzAxMDEwMDAwMDBaFw00\\nOTEyMzEyMzU5NTlaMDExLzAtBgNVBAMTJkNvdWNoYmFzZSBTZXJ2ZXIgTm9kZSAo\\nMTcyLjIzLjEyMS4yMjQpMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA\\n6mocGeuTYweWAOMVWirfXxvpXWTqrD5AjWzDat6XUG7RjLrQ6KJNSBFY7r0zckeV\\nQFlw+To+FH1EdzaG2EZa5N0l5BoHa1Jp+60u/myHSPev3ADmva3sZtC+TZn672wd\\nvGk1YVlr25E84JhSv7IlMvkDhieStwbSgiEy4WnX7KfpgSIBy4kQcIlBpy6CYMow\\noOy2xbaw4zQarx2ujYXx8V8UgxXOVP32LFnv4hHLoNrG6CADDWBLfLsZLXQlW6WK\\nLei67NfKmMCqpgIm1Wr9gOd1C662j+/ayisD7ba+dDJnGELfoCOnW6+DrMnvlb9M\\nyjWomSe16Q6Rl9Y21sQJVQIDAQABo0YwRDAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0l\\nBAwwCgYIKwYBBQUHAwEwDAYDVR0TAQH/BAIwADAPBgNVHREECDAGhwSsF3ngMA0G\\nCSqGSIb3DQEBCwUAA4IBAQAW+YZoV9FKN+zJJxyLU/uE+ue5ulbp5Tps14HQf/dH\\ni9zuzznAxdQyLduDwOo62S7odPDa4Sl/mEov14OZx+tZLpDU3jDkZ0ohzXMsXAVi\\nMPs51gnl+6p+wqehqkMG52QLuJviBu/kf9SZOjcCMkWc0FAwfpZFx8whNeZCp6DU\\nLXsajG2b2o7bANonjshvaL+/a562+nLV465g5gdGABi/dTLJS/JYhHg40yCePFNP\\no2nYF2yy3TVRZ6rEEFYnZ+/Ths5dTNtXLpF3hI40dFNArKGZKgN+cpbJvC4NvhKy\\nUIPJex/mfvaxOmPLGWUltET+G+p5WMnV2Lz7GyQwIovI\\n-----END CERTIFICATE-----\\n","privateKeyPassphrase":{}}]'
      The certificate being used by the cluster
      Node                  Expires                  Type      Subject
      172.23.121.224:8091   2049-12-31T23:59:59.000Z generated CN=Couchbase Server Node (172.23.121.224)
           Warning: Out-of-the-box certificates are self-signed. To further secure your system, you must create new X.509 certificates signed by a trusted CA.
      [root@s44015 ~]# client_loop: send disconnect: Broken pipe
      Saigon:testrunner thuan$ ssh root@172.23.121.224
      Last login: Tue Jan  4 07:39:41 2022 from 10.100.255.77
      [root@s44015 ~]# more /opt/couchbase/VERSION.txt 
      7.1.0-1985
      [root@s44015 ~]# 
      
      

      I will find the last good build and upload logs soon

      Attachments

        No reviews matched the request. Check your Options in the drop-down menu of this sections header.

        Activity

          People

            pvarley Patrick Varley (Inactive)
            thuan Thuan Nguyen
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Gerrit Reviews

                There are no open Gerrit changes

                PagerDuty