由于用于相互TLS通信的CA证书已过期、AIQUM中的集群采集失败
适用场景
- Active IQ Unified Manager (AIQUM) 9.12及更高版本
- ONTAP 9.10及更高版本
- 已为ONTAP集群启用相互传输层安全(MTLS/相互TLS)
问题描述
- AIQUM信息板显示
Cluster discovery failed. Rediscover the cluster after resolving the issue.
- 集群发现会显示
"Failed"
新添加集群的"Failed" 。 - 操作状态 是
Failed
存储管理">"集群设置"中的Failed forHealth Poll
operation. Cluster Monitoring Failed
和Mutual TLS Certificate Expire
触发的事件- 不会显示最新性能图形
- 不会反映最近的配置更改(例如创建qtree)
ocumserver.log
显示错误:
INFO [oncommand] [org.springframework.jms.listener.DefaultMessageListenerContainer#0-1] [com.netapp.ipc.jms.OCIE_Events] OCIE JMS notification message received: {WarningCount=0, DatasourceName=<cluster_name>, DatasourceID=1, Error0_ClusterManagementIP=<cluster_name>, PackageName=netappfoundation, TotalReportTime=-1, PollStartTime=1711675762833, ErrorCount=1, Success=false, DurationTime=554, Error0_Message=[Device name <cluster_name>]: Communication problem with the cluster: <cluster_name>, command: system-get-version, error: 'Received fatal alert: certificate_expired' on try 5 out of 5, TotalZAPITime=-1, NotificationType=PACKAGE_COMPLETED, Error0_Type=NETWORK_ACCESS_FAILURE, UpdateTime=1711675763398, Error0_Port=443, MessageType=PACKAGE_NOTIFICATION, Error0_Zapi=system-get-version}
au.log
显示错误:
ERROR [common-pool-XX] c.o.s.a.d.n.t.z.ZAPIConnection (ZAPIConnection.java:442) - [netappfoundation] <cluster_name> - Communication problem with the cluster: <cluster_name>, command: system-get-version, error: 'Received fatal alert: certificate_expired' on try 5 out of 5
- ONTAP报告
mgmtgwd.certificate.expired
和/或mgmtgwd.certificate.expiring
EMS事件
[Node_Name: mgwd: security.invalid.login:alert]: Failed to authenticate login attempt to Vserver: <vserver_name>, username: null, application: ontapi. audit-mlog shows: [kern_audit:info:3385] 8503e8000065373d :: <cluster_name>:ontapi :: <AIQUM_IP>:52346 :: <cluster_name>:null :: Login Attempt :: Error: Authentication failed