[Spacewalk-list] Problem with certs when configuring proxy

Guy Matz guymatz at gmail.com
Thu May 31 13:53:46 UTC 2018


Peeps,
I'm inheriting a spacewalk installation and need to put in a proxy . . .
actually, the proxy already exists, but I get the output below when I try
to run configure-proxy.sh.  Both the master and the proxy have ssl-build
AND ssl-build.bak directories and I can't really tell which certs & keys
are active on the master, that I should scp to the proxy to get the
configure-proxy to work.

Does anyone know how I can find the cert & key on the master that are
actually being used for SSL so that I can bring them to the proxy, since I
can't trust what's in ssl-build?

Thanks a lot!
Guy

configure-proxy.sh

Using CA key at /root/ssl-build/RHN-ORG-PRIVATE-SSL-KEY.
Generating SSL key and public certificate:
CA password:
Rotated out: 'server.key.6'
Backup made: 'server.key' --> 'server.key.1'
Backup made: 'rhn-server-openssl.cnf' --> 'rhn-server-openssl.cnf.1'
Rotated out: 'server.csr.6'
Backup made: 'server.csr' --> 'server.csr.1'

ERROR: web server's SSL certificate generation/signing failed:

Using configuration from /root/ssl-build/rhn-ca-openssl.cnf
unable to load CA private key
140612740421536:error:06065064:digital envelope
routines:EVP_DecryptFinal_ex:bad decrypt:evp_enc.c:592:
140612740421536:error:0906A065:PEM routines:PEM_do_header:bad
decrypt:pem_lib.c:488:
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/spacewalk-list/attachments/20180531/6cb5a85d/attachment.htm>


More information about the Spacewalk-list mailing list