Can't add ProxmoxBackupServer after changed HTTPS certificate

nicedevil

Member
Aug 5, 2021
112
11
23
Hi guys,

I have renewed my wildcard-certificate on all my hosts (proxmox, host1, host2 and proxmox backup 1 and offsite backup 2). I case someone asks, I have a qdevice setup.

Now my backup storage is marked with a questionmark

1677617100966.png

I already removed it and readded it with the freshly copied fingerprint and so on. What am I doing wrong?

On my offsite backup-server I get this message:

2023-02-28T21:43:43+01:00: TASK ERROR: remote connection to '10.0.78.5' failed - error trying to connect: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:../ssl/statem/statem_clnt.c:1914:

Same message on the PVE Host.

I already did this
Python:
update-ca-certificates -f

And rebootet alle Backup Servers or Hosts for PVE
 
Last edited:
Ok I fixed it by adding my ca-certificate to the /etc/ssl/certs folder and running this afterwards => update-ca-certificates -f
What I don't understand is, why I have to upload a fullchain cert and then do the manual step inside this folder?

On my fresh installation, that wasn't neccessary
 
On my fresh installation I just uploaded my cert via webui and now after renewing the cert I did the same, nothing more. Leaded to the error I got above.
 
I suppose you added the Proxmox Backup Server by copying its fingerprint? That is only necessary if you are using a self-signed certificate, or are accessing your PBS via IP address. The fingerprint of your PBS does change every time you update its certificate.

You seem to have a valid certificate for your domain, so you can leave the fingerprint-field empty.
 
  • Like
Reactions: lxiosjao
that is correct I added the fingerprint months ago, addded the cert later and now renewed it.
then i deleted the backupserver's storage on my host and readded it with the new fingerprint, also tested it without, was the same issue.

for me I'm absolutly fine with my solution I provided above but just wondering if there is an other one doable with the webui for the future :)
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!