Error During Ssl Handshake Voms
Contents |
Email Phone CC Details Submitted ViaGOC Ticket/submitSubmitterRicardo Manuel Ramos dos Santos Neves Ticket Type Problem/Request Priority Normal Status Closed Next Action Resolved Next Action Deadline 2015-01-30 Assignees Vince error during ssl handshake with remote server Neal / OSG GOC Support TeamVince Neal / OSG GOC Service DeskVince
Error During Ssl Handshake With Remote Server Returned By
Neal / Research SST Assignees TODO Past Updates Sort Expand Descriptions Update w/Email Jan 30, 2015 08:32 PM UTC
Error During Ssl Handshake With Remote Server Returned By Apache
by Vince NealThank you for the update. Closing, as requested. VinceJan 27, 2015 06:29 PM UTCHi. I think it's a slc5/6 issue. I think you can close this ticket. Thank
Error During Ssl Handshake With Remote Server Proxy
you all for your help. by /DC=com/DC=DigiCert-Grid/O=Open Science Grid/OU=People/CN=Ricardo Manuel Ramos dos Santos Neves 2273Jan 27, 2015 04:56 PM UTC by Vince NealHi Ricardo, Checking in to see where we stand with this ticket. Please let me know if I can assist. Thanks! VinceJan 22, 2015 04:21 PM UTC by Vince NealThank you for the update. Could you please try recreating your reason error during ssl handshake with remote server userkey.pem and usercert.pem? Thank you, VinceJan 20, 2015 11:22 PM UTCI tried using other versions of voms (3.04) but without success The error is: Credentials couldn't be loaded [/export/home/rneves/.globus/userkey.pem, /export/home/rneves/.globus/usercert.pem]: Can not load the PEM private key: org.bouncycastle.openssl.EncryptionException: exception using cipher - please check password and data. No credentials found! (i double checked that my password is right) I used this certificate and voms version before, and it used to work just fine. Do you have any other suggestions? by /DC=com/DC=DigiCert-Grid/O=Open Science Grid/OU=People/CN=Ricardo Manuel Ramos dos Santos Neves 2273Jan 20, 2015 07:40 PM UTC by Vince NealHi Ricardo, Checking in to see if you have an an opportunity to update your VOMS package. Please let me know if I can assist. Thanks! VinceJan 15, 2015 07:38 PM UTC by Vince NealThanks for the update. I believe if you update your VOMS you will get the latest servers and this should resolve your issue. Please let me know if I can assist. Thank you, VinceJan 14, 2015 11:04 PM UTCThis is what I get: voms-proxy-init --version voms-proxy-init Version: 2.0.9 Compiled: Nov 8 2012 14:02:33
FedorovTicket Links Ticket Type Problem/Request Priority Normal Status Closed Next Action Mat to debug Next Action Deadline 2015-09-09 Assignees Scott Teige / OSG Operations InfrastructureDave Dykstra / OSG Security CoordinatorsSoftware Support (Triage) / OSG Software TeamMatyas Selmeci / OSG Software TeamTim https://ticket.grid.iu.edu/23763 Theisen / OSG Software Team Assignees TODO Past Updates Sort Expand Descriptions Update w/Email Sep 2, 2015 07:11 PM UTC by OSG-GOCHello, If there is any problems with certificates in cvmfs repository again ? voms-proxy-init -voms cms -valid 192:00 https://ticket.grid.iu.edu/26674?sort=up& -debug with X509_CERT_DIR=/cvmfs/oasis.opensciencegrid.org/mis/osg-wn-client/3.2/3.2.26/el6-x86_64/etc/grid-security/certificates X509_VOMS_DIR=/cvmfs/oasis.opensciencegrid.org/mis/osg-wn-client/3.2/3.2.26/el6-x86_64/etc/grid-security/vomsdir Detected Globus version: 2.2 Unspecified proxy version, settling on Globus version: 2 Number of bits in key :1024 Files being used: CA certificate file: none Trusted certificates directory : /cvmfs/oasis.opensciencegrid.org/mis/osg-wn-client/3.2/3.2.26/el6-x86_64/etc/grid-security/certificates Proxy certificate file : /tmp/x509up_u0 User certificate file: /etc/grid-security/hostcert.pem User key file: /etc/grid-security/hostkey.pem Output to /tmp/x509up_u0 Your identity: /DC=com/DC=DigiCert-Grid/O=Open Science Grid/OU=Services/CN=earth.crc.nd.edu Using configuration file /cvmfs/oasis.opensciencegrid.org/mis/osg-wn-client/3.2/3.2.26/el6-x86_64/etc/vomses Creating temporary proxy to /tmp/tmp_x509up_u0_29211 ...++++++ ...++++++ Done Contacting voms2.cern.ch:15002 [/DC=ch/DC=cern/OU=computers/CN=voms2.cern.ch] "cms" Failed Error: Error during SSL handshake:error:80066405:lib(128):verify_callback:outdated CRL found, revoking all certs till you get new CRL:sslutils.c:2115 outdated CRL found, revoking all certs till you get new CRL Function: verify_callback error:80066411:lib(128):verify_callback:certificate failed verify::sslutils.c:2318 error =CRL has expired subject=/DC=ch/DC=cern/OU=computers/CN=voms2.cern.ch issuer =/DC=ch/DC=cern/CN=CERN Grid Certification A
This Document Know your Responsibilities Getting your Certificate PKCS12 (.p12) vs PEM format Revoke your Certificate if Compromised References Comments NOTE For instructions on getting service and host certificates, https://twiki.opensciencegrid.org/bin/view/Documentation/Release3/CertificateUserGet you're in the wrong place. See Get Host and Service Certificates. About This Document If you don't know what a X509 certificate is or what it https://www.jiscmail.ac.uk/cgi-bin/webadmin?A2=lcg-rollout;8c80c3a4.1303 is used for, see What is a certificate?. This document describes how to get and set up a personal certificate (also called a grid user certificate), from error during the OSG Certificate Authority (OSG CA). The OSG CA is recognized by all OSG resources. Other CAs may be used; if your virtual organization (VO) requires that you get a certificate from a different CA, contact your VO Support Center for instructions. Know your Responsibilities When you request a certificate your provide some public error during ssl personal information about yourself; name, email address, phone number, and which VO (virtual organization) you belong to. If any of this information changes after you have your certificate you should notify OSG (and probably VO) of the changes. For the OSG RA send email to osg-ra at opensciencegrid dot org. Your name and email address are encoded into the signed certificate and if either of those change (usually email address) then you should request a new certificate with the correct information and revoke the old certificate. Getting your Certificate There are two different ways to obtain your certificate, either via a command line interface, or through a web browser. The links below will guide you through whichever method you choose. The command line method is generally simpler and less prone to errors than using a web browser but it may require extra setup and package installation the first time you do it. Most people end up needing their ce
By Topic: [ First | Previous | Next | Last ] By Author: [ First | Previous | Next | Last ] Font: Proportional Font LISTSERV Archives LCG-ROLLOUT Home LCG-ROLLOUT March 2013 Options Subscribe or Unsubscribe Log In Get Password Subject: Re: Problems generating proxys for dteam From: Vanessa Hamar <[log in to unmask]> Reply-To:LHC Computer Grid - Rollout <[log in to unmask]> Date:Fri, 15 Mar 2013 11:29:09 +0100 Content-Type:multipart/signed Parts/Attachments: text/plain (85 lines) , smime.p7s (85 lines) Hello, I have the same problem: -bash-3.2$ voms-proxy-init --voms dteam Enter GRID pass phrase: Your identity: /O=GRID-FR/C=FR/O=CNRS/OU=CC-IN2P3/CN=Vanessa Hamar Creating temporary proxy ................................ Done Contacting voms.hellasgrid.gr:15004 [/C=GR/O=HellasGrid/OU=hellasgrid.gr/CN=voms.hellasgrid.gr] "dteam" Failed Error: Error during SSL handshake: Trying next server for dteam. Creating temporary proxy ........................................................................ Done Contacting voms2.hellasgrid.gr:15004 [/C=GR/O=HellasGrid/OU=hellasgrid.gr/CN=voms2.hellasgrid.gr] "dteam" Failed Error: Error during SSL handshake: None of the contacted servers for dteam were capable of returning a valid AC for the user. Best regards, Vanessa On Mar 15, 2013, at 11:19 AM, Carles Acosta wrote: > Hello, > > Today, I can not get any proxy for vo dteam from our UI. I see the following error: > > [cacosta@ui02 ~]$ voms-proxy-init --voms dteam > Enter GRID pass phrase: > Your identity: /DC=es/DC=irisgrid/O=pic/CN=carles.acosta > Creating temporary proxy ..................................... Done > Contacting voms2.hellasgrid.gr:15004 [/C=GR/O=HellasGrid/OU=hellasgrid.gr/CN=voms2.hellasgrid.gr] "dteam" Failed > > Error: Error during SSL handshake: > > Trying next server for dteam. > Creating temporary proxy .............................................. Done > Contacting lcg-voms.cern.ch:15004 [/DC=ch/DC=cern/OU=computers/CN=lcg-voms.cern.ch] "dteam" Failed > > Error: Error during SSL handshake: > > Trying next server for dteam. > Creating temporary proxy ............................................................................................................ Done > Contacting voms.cern.ch:15004 [/