Quorum witness 5.0.2 SSL with domain certificates

Post Reply
profp62
Posts: 46
Joined: Wed Feb 19, 2014 12:53 pm

Quorum witness 5.0.2 SSL with domain certificates

Post by profp62 »

Hi

I have problem with SSL configuration. Without SSL quorum is working, but the customer requires it.
I think, that qw-server cert is corect - the guide is clear - but there is no guide for qw-client.

No i have

showcert -service qw-client
Service Commonname Type Enddate Fingerprint
qw-client xxxxxxxxxxxxxxxxxx.cz csr -- finger
qw-client SRV-INTERNALCA-CA intca Nov 20 05:53:20 2029 GMT finger
qw-client* SRV-ROOTCA-CA rootca Nov 20 05:53:20 2029 GMT finger

showcert -service qw-server
Service Commonname Type Enddate Fingerprint
qw-server* SRV-ROOTCA-CA rootca Nov 20 05:53:20 2029 GMT finger

But

setrcopytarget witness check -ssl xxx.xxx.xxx.xxx
error: No route to Quorum Witness at xxx.xxx.xxx.xxx from any node.
If using ssl option, verify certificate configuration and consult Quorum Witness logs.

Network is ok, if i disable SSL on quorum server, it's working.

Have someone this config working ?

Thanks
david
Posts: 44
Joined: Tue May 05, 2015 10:56 am

Re: Quorum witness 5.0.2 SSL with domain certificates

Post by david »

I have this set up done. Tried via cli, didn't work for some reason. Logged in to the gui on the primera and added the added the certs in there and it started working.

I didn't try at the time to figure out why. If I remember I will check my notes from when I did it. I have 2 more to install at work this month so will likely be trying it again.
Post Reply