Can't add one of clusters

ssbaksa

New Member
Jan 13, 2025
3
0
1
Hi,

I am testing Datacenter Manager and it works nice but one of my clusters can't be added. I have 3 already in working state with no errors.

This is from log file:
Feb 20 15:53:20 osi-virt-controll-pdm1 proxmox-datacenter-api[792]: expected fingerprint: f0:fa:5c:f4:e1:e5:11:27:b4:22:5d:46:1d:2e:0e:19:87:ad:b9:ca:ba:c0:83:c4:c8:24:b8:96:e4:e4:52:4d
Feb 20 15:53:24 osi-virt-controll-pdm1 proxmox-datacenter-api[792]: bad fingerprint: a7:4a:ba:7f:ee:9b:e5:03:22:66:15:7b:47:92:1d:d0:67:11:eb:cc:c2:c4:27:76:e9:67:6c:db:f0:11:11:eb

All add actions are showing OK till end. Then I get this.
api error (status = 400: error trying to connect: error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:../ssl/statem/statem_clnt.c:1889:)

I can't find from where that bad fingerprint is coming from. There is no certificate with this one. I have even opened database to search for it. Yes, I know that I can reinstall it but in this one I have 17 servers and it will be painful.

Br
SSBaksa
 
Hi,

is there maybe a firewall or proxy in between the pdm and the cluster? usually the remote wizard in the pdm gui tries to connect to the cluster at least once, otherwise it won't let you through.
One scenario i could imagine is having a proxy in-between that changes the fingerprint?
 
Hi,

There is no internal firewall or proxy. All clusters are on different management VLAN's except 2 small clusters (3 node and 5 nodes).
The largest one have 13 nodes. The one that I have problem adding have 17 nodes and 17 more waiting to be added to that cluster.

I have local CA authority which I am using for signing certificates or csr's and that is working without problem (112 nodes in Openstack).
The same authority is used for Proxmox certificates.

But, to be really sure I will recheck again.

Br
Saša
 
Hi,

Was this ever resolved? I'm seeing issues adding a remote to pdm. this is the error:

api error (status = 400: error trying to connect: error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:../ssl/statem/statem_clnt.c:1889:)

I have replaced all my host certificates with intermediate certs from my local ca and now i cant connect to them from PDM.
get the same bad fingerprint issue in the logs
Thanks

John
 
Last edited:
Yes. I have resolved it 5 minutes ago. It was my DNS server for Test lab. Wrong IP in that forward section. When I put correct network part of IP for that cluster It solved my problems automagicaly.

Best regards
Saša
 
Yes. I have resolved it 5 minutes ago. It was my DNS server for Test lab. Wrong IP in that forward section. When I put correct network part of IP for that cluster It solved my problems automagicaly.

Best regards
Saša
any guide on how you solve it? I mean which files do we need to check and edit? thanks