[Pacemaker] pacemaker-remote tls handshaking

Lindsay Todd rltodd.ml1 at gmail.com
Thu May 16 20:44:09 UTC 2013


I've built pacemaker 1.1.10rc2 and am trying to get the pacemaker-remote
features working on my Scientific Linux 6.4 system.  It almost works...

The /etc/pacemaker/authkey file is on all the cluster nodes, as well as my
test VM (readable to all users, and checksums are the same everywhere).  I
can connect via telnet to port 3121 of the VM.  I even see the ghost node
appear for my VM when I use either 'crm status' or 'pcs status'.  (Aside:
 crmsh doesn't know about the new meta attributes for remote...)

But the communication isn't quite working.  In my log I see:

May 16 15:58:34 cvmh04 crmd[4893]:  warning: lrmd_tcp_connect_cb: Client
tls han
dshake failed for server swbuildsl6:3121. Disconnecting
May 16 15:58:34 swbuildsl6 pacemaker_remoted[2308]:    error:
lrmd_remote_client
_msg: Remote lrmd tls handshake failed
May 16 15:58:35 cvmh04 crmd[4893]:  warning: lrmd_tcp_connect_cb: Client
tls han
dshake failed for server swbuildsl6:3121. Disconnecting
May 16 15:58:35 swbuildsl6 pacemaker_remoted[2308]:    error:
lrmd_remote_client
_msg: Remote lrmd tls handshake failed

and it isn't long before pacemaker stops trying.

Is there some additional configuration I need?

/Lindsay
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.clusterlabs.org/pipermail/pacemaker/attachments/20130516/6d33c58c/attachment-0003.html>


More information about the Pacemaker mailing list