Problem with actual version #329
Replies: 10 comments 4 replies
-
Dear Bernd, is there a host that I could use to reproduce the problem? |
Beta Was this translation helpful? Give feedback.
-
I'll try to check on a CentOS 7 machine ... |
Beta Was this translation helpful? Give feedback.
-
I was able to reproduce the problem on CentOS 7 |
Beta Was this translation helpful? Give feedback.
-
OpenSSL 1.0.2k-fips 26 Jan 2017 It will take a while. On my machine the temporary file creation (without mkdir) is not working.
seems to hang ... |
Beta Was this translation helpful? Give feedback.
-
I'm puzzled:
but the connection works
but
does not complain and the connection does not work
|
Beta Was this translation helpful? Give feedback.
-
Anywhay the problem is in all the ciphers with PSS (Probabilistic Signature Scheme (PSS)) |
Beta Was this translation helpful? Give feedback.
-
thanks for the quick fix. RSA is now working. but i still have the timeout problem. |
Beta Was this translation helpful? Give feedback.
-
If i try to do the check on command line with the same arguments, then it is successfull. |
Beta Was this translation helpful? Give feedback.
-
Difficult to tell without additional information. With the debugging output we could see where the timeout is occurring. You can specify a file for the debugging output with the |
Beta Was this translation helpful? Give feedback.
-
Hello Matteo,
mostly on ldaps ports, but also on https ports.
the same without --ignore-connection-problems option works fine. |
Beta Was this translation helpful? Give feedback.
-
Hello,
we had a old version running in our Nagios 4.4.3. It was Version 1.84.0.
This Version works very well without any issues.
The nagios software is installed on a RHEL 7.9 with OpenSSL Version: OpenSSL 1.0.2k-fips 26 Jan 2017
Now we updated to version 2.10.2 because we want to use some new features off this script.
Now we have two problems:
We have some servers with RSA and EC certificates installed. so we use the options --ecdsa and --rsa.
--ecdsa works as before, but when we use --rsa, than we get this errors message:
SSL error: Error with command: "-sigalgs RSA-PSS+SHA512:RSA-PSS+SHA384:RSA-PSS+SHA256:RSA+SHA512:RSA+SHA256:RSA+SHA384:RSA+SHA224:RSA+SHA1"
All our certificate checks yesterday evening run into critical stae. tests before were ok, and i have no idea why this happened.
the checks ran into a time out 60.01. and a forcecheck to try again failed. the timestamp for the last check attribute has not changed. i was not able to check again.
so i had to implement the old version of the script, and then everythink worked again.
kind Regards
Bernd
Beta Was this translation helpful? Give feedback.
All reactions