Solved

WebLogic: Node Manager Error

Posted on 2010-09-08
3
964 Views
Last Modified: 2012-05-10
I am unable to start Managed Server with the help of Node manger.

I have Admin Server, 2 Managed Servers on a same machine. SSL is enabled for Admin server and disabled for 2 managed servers. I can start the Managed Servers using ./startManagedWeblogic.sh script. However, I am using DemoTrust keystore for this domain and in NodeManger.properties has following setting:

KeyStores=CustomIdentityAndCustomTrust
CustomIdentityKeyStoreFileName=/bea/keystores/xxx_identity.jks
...

This .JKS file is configured for some other domain which uses this nodemanager to start its managed server and the works fine. NodeManager.hosts has both the IPs binded.


Here is the Error Message:

[Security:090477]Certificate chain received from xxxxx02 - 162.28.145.13 was not trusted causing SSL handshake failure.. Please ensure that the NodeManager is active on the target machine].]


My question is, Why it is throwing an SSL error, even though SSL port is disabled for both the managed servers?
0
Comment
Question by:imsuniel
  • 2
3 Comments
 
LVL 1

Expert Comment

by:bigmacou
ID: 33633537
I may not be understanding, but you are using the DemoTrust keystore on the admin server, yet the CustomIdenty keystore settings are present and uncommented in nodemanager.properties correct?  If this is true this will produce ssl exceptions.  To be very simplistic you may try using CustomIdenty keystore accross all servers.  

If that is not a viable option, you may also follow the steps listed below to run two node managers for two different apps running the same weblogic version on the same server(s).

1. copy ${WL_HOME}/common/nodemanger folder to a folder specific for this new application (ex. ${WL_HOME}/common/{appName}nodemanager) and then copy the startstopNodemanger.sh script, also renaming it specific to the new application (${WL_HOME}/server/bin/${appName}startstopNodeManager.sh).  

2. Once these have been renamed you will need to change the value of NODEMGR_HOME in the new ${appName}startstopNodeManager.sh script to the new directory you created (NODEMGR_HOME="${WL_HOME}/common/${appName}nodemanager")

3. Then edit nodemanager.properties in the new directory and comment out all of the keystore data.  You should only need to specify the values listed below in this file as Demotrust / DemoIdentity  are defaults.

PropertiesVersion=8.1 (or your current version)
ReverseDnsEnabled = true
ListenAddress = (ip or DNS)
ListenPort = (port #) (this must be different than what is being used by the other cluster if both clusters are running on the same machine, this must also be changed in the admin console under the nodemanager tab for each machine.)


Hopefully this helps and did not confuse you.  :)

btw I found this OTN Discussion, which may help.

http://forums.oracle.com/forums/thread.jspa?threadID=982823&tstart=65
0
 

Accepted Solution

by:
imsuniel earned 0 total points
ID: 33640902
Sounds like a good solution. I will definitely give it a try!
I have Production Mode Enabled. So, I was wondering if Demotrust / DemoIdentity Keystore work in this case.

Thanks for responding!
0
 
LVL 1

Expert Comment

by:bigmacou
ID: 33643847
No problem, I am glad that worked for you.  I apologize for the rough delivery, I even confused myself when writing those instructions. :)  Good luck with your new cluster.
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Issues with Ports in Linux (Hyper-V Guest) 2 102
Workstation can't join my domain. 10 117
Suggestions for career in IT 11 90
App holding yum lock unable to update my rpm package 1 54
Both MMF (multi-mode fiber) and SMF (single-mode fiber) are types of optical fiber that can aid in communication applications. These thin strands of silica or glass will allow communication to occur between devices. The transmission of light between…
Are you one of those front-line IT Service Desk staff fielding calls, replying to emails, all-the-while working to resolve end-user technological nightmares? I am! That's why I have put together this brief overview of tools and techniques I use in o…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This tutorial gives a high-level tour of the interface of Marketo (a marketing automation tool to help businesses track and engage prospective customers and drive them to purchase). You will see the main areas including Marketing Activities, Design …

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question