LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 08-02-2012, 12:32 AM   #1
zama
Member
 
Registered: Mar 2012
Posts: 34

Rep: Reputation: Disabled
Location of SSL Host key fingerprints


Hi All,

Need help in identifying the location of SSL Host key fingerprints in RHEL .

Was actually trying to create two HA clusters using the same nodes using Conga cluster software . But technically conga does not allows using the same nodes in a different cluster. I am getting the following error

""
Status messages:

Host system3.example.com has SSL key fingerprint 66:38C:1B:26:03:6E:91:1C:A1:A4:430:5FB:97:FE:CE:EE:1B
Host system4.example.com has SSL key fingerprint 78:C1:24:E8:AB:E7:06B4:C1:23:80:8E:A5:35:21:B9:9F:26:2C

----

[dismiss]

The following errors occurred:

Host system3.example.com is already a member of the cluster named "ldapcluster"
Host system4.example.com is already a member of the cluster named "ldapcluster"

=======

Need help in identifying the location from where it is retrieving the SSL key fingerprints.

Any help here will be highly appreciated ..

Thanks in Advance
Zaman
 
Old 08-02-2012, 12:50 AM   #2
zhjim
Senior Member
 
Registered: Oct 2004
Distribution: Debian Squeeze x86_64
Posts: 1,748
Blog Entries: 11

Rep: Reputation: 233Reputation: 233Reputation: 233
I'd say the SSL fingerprint is derived from the SSL Certificate of the hosts. Are we talking HTTP or SSH? Also that won't matter mutch. Look into man page of openssl there should be a line on how to calculate the fingerprint of a certificate.

Nother thing. The hosts are already member of the cluster so what is the actual problem?
Another nother thing. Please put things into code blocks its easier to read than having emotion all over the fingerprint .
 
Old 08-02-2012, 02:03 AM   #3
zama
Member
 
Registered: Mar 2012
Posts: 34

Original Poster
Rep: Reputation: Disabled
Thanks for the quick response.

Quote:
Originally Posted by zhjim View Post
I'd say the SSL fingerprint is derived from the SSL Certificate of the hosts. Are we talking HTTP or SSH? Also that won't matter mutch. Look into man page of openssl there should be a line on how to calculate the fingerprint of a certificate.

Got the point . Will take a look at man page for openssl.

>> Another thing. The hosts are already member of the cluster so what is the actual problem?

The problem for me is that I want to use the same hosts to create another cluster , but conga technically does not allow this. So, was trying to identify how the software identifies that the host being already a member of another cluster. Tried IP aliasing and then added a new hostname corresponding to virtual ip address in /etc/hosts , but the cluster software still able to identify that the hosts are already a member of another cluster. So , it looked to me it is performing these tests based on the SSL fingerprint and hence was trying to identify the location of SSL fingerprint.

Will try to generate new set of keys for the new hostname if it is technically possible that I added in /etc/hosts , and will see how conga works

>> Another nother thing. Please put things into code blocks its easier to read than having emotion all over the fingerprint .
Will take in future queries.

Thanks Again
Zaman
 
Old 08-06-2012, 02:04 AM   #4
zama
Member
 
Registered: Mar 2012
Posts: 34

Original Poster
Rep: Reputation: Disabled
Marking this Post as resolved as I was able to solve the issue of creating multiple clusters using same hosts by creating multiple failover domains. Also , got the understanding how SSL fingerprints are calculated
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Warning: the DSA host key for '' differs from the key for the IP medirecpr Linux - Newbie 5 10-12-2014 10:20 AM
[SOLVED] Error on SVN checkout: SSL handshake failed: SSL error: Key usage violation in certif jsaravana87 Linux - Server 3 05-07-2012 10:00 AM
SSL certs/keys location BEBigBear Linux - Security 6 01-04-2009 09:03 AM
A question about rsa host key fingerprints lawrence_lee_lee Linux - Software 8 07-17-2008 09:58 PM
Multiple ssh tunnels and bad key fingerprints theNbomr Linux - Networking 2 06-14-2008 08:15 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 12:16 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration