Forums

Resolved
0 votes
Hello all,

I've 2 Clearos systems and I'd like to synchronize them. So I've a master and a slave. Ldap and windows domain is synchronizing and this is good. I'd like to go futher now with my slave configuring flexshare and certificate but the certificate are not sychronizing; I always have the same message : The system is waiting for a connection to the master node.

I started the sync process 2 days ago... can I do something to force the certificate sync ?

Thanks to all for your help
Wednesday, March 18 2020, 07:02 AM
Share this post:

Accepted Answer

Wednesday, March 18 2020, 10:10 AM - #Permalink
Resolved
0 votes
Please can you do a "yum update app-certificate-manager --enablerepo=clearos-updates" or just run /usr/clearos/apps/certificate_manager/deploy/upgrade. Something has stomped on the /etc/pki/CA/private permissions which the last release of app-certficate manager fixed. All this release does is bump the version which re-runs the upgrade script.

If one of your machines is external, you also need to make sure the slave can access the master on tcp ports 81, 636, 8154 and 8155.

The only certificates which synchronise, I believe are the CA and perhaps sys-0-cert and their keys. User certificates do not synchronise, but OpenVPN on a slave accepts user certificates created on the master.
The reply is currently minimized Show
Responses (9)
  • Accepted Answer

    Thursday, March 19 2020, 11:11 AM - #Permalink
    Resolved
    0 votes
    ok, thanks very very much for the informations Nick.
    they are very precious to me !
    The reply is currently minimized Show
  • Accepted Answer

    Thursday, March 19 2020, 10:46 AM - #Permalink
    Resolved
    0 votes
    Arnaud Forster wrote:

    Hello Nick,

    Thanks for the enquiry. Yes, my certificate is valid for my subdomain "subdomain.domain.com" . According to my government's instructions, I added into the DNS of my domain's provide a A entry with my "subdomain.domain.com" and the local IP address. And this works. With a computer in my LAN I can reach my server using https://subdomain.domain.com" :) but the valid certficate is only used when adding the port 81

    I imported my certificate via the Certificate Manager then assign it to the web server. I think that's why it works fine when I connect to my webserver using port 81. But I just wanted to tell people to connect to https://mysbudomain.mydomain.com (without port 81) to be as simple as possible...
    To use the certificate for port 81 it is set up in System > Settings > General Settings. To use it in the the web server you set it in Server > Web > Web Server.

    It is not practical to access the webconfig on anything other than port 81.
    The reply is currently minimized Show
  • Accepted Answer

    Wednesday, March 18 2020, 06:33 PM - #Permalink
    Resolved
    0 votes
    Hello Nick,

    Thanks for the enquiry. Yes, my certificate is valid for my subdomain "subdomain.domain.com" . According to my government's instructions, I added into the DNS of my domain's provide a A entry with my "subdomain.domain.com" and the local IP address. And this works. With a computer in my LAN I can reach my server using https://subdomain.domain.com"; :) but the valid certficate is only used when adding the port 81

    I imported my certificate via the Certificate Manager then assign it to the web server. I think that's why it works fine when I connect to my webserver using port 81. But I just wanted to tell people to connect to https://mysbudomain.mydomain.com (without port 81) to be as simple as possible...
    The reply is currently minimized Show
  • Accepted Answer

    Wednesday, March 18 2020, 05:22 PM - #Permalink
    Resolved
    0 votes
    Arnaud Forster wrote:

    A last question (I hope) ....
    when connecting to my ClearOS web application ; if I use the port 81 , it's my valid and imported cetificated that is used and I've no problem. But if i'm trying to connect without the port 81 (https://subdomain.domain.com), I get a warning/error because this is the default self-signet certificate that is used.
    Is there a way always using my importing certificate ?
    It depends on how you got port 81 working. Normally you'd import it via the Certificate Manager then assign it in the WebServer. Is your certificate valid for subdomain.domain.com?
    The reply is currently minimized Show
  • Accepted Answer

    Wednesday, March 18 2020, 01:57 PM - #Permalink
    Resolved
    0 votes
    ok, about the sync,, i'll have to search to see if I can't do the opposite ... the master initialise the sync ... or maybe having my master in my DMZ ....
    The reply is currently minimized Show
  • Accepted Answer

    Wednesday, March 18 2020, 01:54 PM - #Permalink
    Resolved
    0 votes
    A last question (I hope) ....
    when connecting to my ClearOS web application ; if I use the port 81 , it's my valid and imported cetificated that is used and I've no problem. But if i'm trying to connect without the port 81 (https://subdomain.domain.com), I get a warning/error because this is the default self-signet certificate that is used.
    Is there a way always using my importing certificate ?
    The reply is currently minimized Show
  • Accepted Answer

    Wednesday, March 18 2020, 01:47 PM - #Permalink
    Resolved
    0 votes
    Only the slaves can initialise the sync. The master listens and waits for connections, I believe.
    The reply is currently minimized Show
  • Accepted Answer

    Wednesday, March 18 2020, 10:27 AM - #Permalink
    Resolved
    0 votes
    Ok works like a charm now :)
    Thanks very much Nick
    :)
    The reply is currently minimized Show
  • Accepted Answer

    Wednesday, March 18 2020, 10:13 AM - #Permalink
    Resolved
    0 votes
    ok, thanks very much Nick ; I'm trying .. in both servers I think, ?

    None of my server are external... this is the next step of the sync... but only the master could initialize a sync because I'll have no incoming connexion possibility
    The reply is currently minimized Show
Your Reply