-
Notifications
You must be signed in to change notification settings - Fork 197
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
RHN-ORG-TRUSTED-SSL-CERT empty in /usr/share/susemanager/salt/certs #9740
Comments
When the container startup a service is executed called "uyuni-update-config.service". https://github.com/uyuni-project/uyuni/blob/master/spacewalk/admin/uyuni-update-config#L71-L76 Please check the logs (journal) if you see an error message when the container starts. |
@MaxHerrmannSVA in case it helps: you can use |
Hi, Sadly the Unit dont print anything to journald...
I digged a bit deeper into the Unit target wants, but this seems fine to me...
The only difference in those file to my fresh test installation is that /etc/systemd/system/multi-user.target.wants/spacewalk.target is no symlink but the file content is the same... Maybe my colleague ran into #9531 while migrating the system, so maybe this has something to do with it...
|
Problem description
When migrating Uyuni from 2024.08 to 2024.12 I ran into an error where the RHN-ORG-TRUSTED-SSL-CERT was not migrated to /usr/share/susemanager/salt/certs/RHN-ORG-TRUSTED-SSL-CERT.
Due to this, the states under /usr/share/susemanager/salt/certs did not fail, but emptied the local CA File on all clients and no client was able to get updates with a "SSL certificate problem: unable to get local issuer certifiacte" error.
After copying the cert to the /usr/share/susemanager/salt/certs directory and executing the highstate again, the certs got rolled out again, and updates are working
cp /etc/pki/trust/anchors/LOCAL-RHN-ORG-TRUSTED-SSL-CERT /usr/share/susemanager/salt/certs/RHN-ORG-TRUSTED-SSL-CERT
The Main Problem is, that this "fix" is not reboot persistant, so everytime we restart the Uyuni Server the /usr/share/susemanager/salt/certs/RHN-ORG-TRUSTED-SSL-CERT is emtpy again and we have to manually copy the Filecontent
Steps to reproduce
Uyuni version
Uyuni proxy version (if used)
Useful logs
I found nothing in the logs...
Additional information
I installed a fresh Testserver to see if this is a generall problem.
There i discovered that the Cert is copied there while uyuni is starting and emtpy on default...
I guess that on my migrated installation we have a problem with the mechanism that copies the certfile to the salt states...
Any ideas how to fix this?
Thanks for your help!
Max
The text was updated successfully, but these errors were encountered: