Solved

Red Hat SSL Cert error

Posted on 2014-03-25
6
1,615 Views
Last Modified: 2014-03-26
Hello,

I seem to get the following SSL cert error when trying to use yum, could anyone assist?

Thanks,
Dave

Component: pirut
Summary: TB3e4030d0 rhnserver.py:64:__call__:SSLCertificateVerifyFailedError: The SSL certificate failed verification.

Traceback (most recent call last):
  File "/usr/sbin/pirut", line 490, in ?
    main()
  File "/usr/sbin/pirut", line 483, in main
    pm = PackageManager(options.config, options.onlyrepo)
  File "/usr/sbin/pirut", line 67, in __init__
    GraphicalYumBase.__init__(self, False, config)
  File "/usr/lib/python2.4/site-packages/pirut/__init__.py", line 137, in __init__
    plugin_types=(yum.plugins.TYPE_CORE,))
  File "/usr/lib/python2.4/site-packages/yum/__init__.py", line 118, in doConfigSetup
    errorlevel=errorlevel)
  File "/usr/lib/python2.4/site-packages/yum/__init__.py", line 183, in _getConfig
    self.plugins.run('init')
  File "/usr/lib/python2.4/site-packages/yum/plugins.py", line 169, in run
    func(conduitcls(self, self.base, conf, **kwargs))
  File "/usr/lib/yum-plugins/rhnplugin.py", line 110, in init_hook
    login_info = up2dateAuth.getLoginInfo()
  File "/usr/share/rhn/up2date_client/up2dateAuth.py", line 211, in getLoginInfo
    login()
  File "/usr/share/rhn/up2date_client/up2dateAuth.py", line 178, in login
    li = server.up2date.login(systemId)
  File "/usr/share/rhn/up2date_client/rhnserver.py", line 64, in __call__
    raise up2dateErrors.SSLCertificateVerifyFailedError()
SSLCertificateVerifyFailedError: The SSL certificate failed verification.

Local variables in innermost frame:
args: ('<?xml version="1.0"?>\n<params>\n<param>\n<value><struct>\n<member>\n<name>username</name>\n<value><string>nccweb1</string></value>\n</member>\n<member>\n<name>operating_system</name>\n<value><string>redhat-release</string></value>\n</member>\n<member>\n<name>description</name>\n<value><string>Initial Registration Parameters:\nOS: redhat-release\nRelease: 5Server\nCPU Arch: i686-redhat-linux</string></value>\n</member>\n<member>\n<name>checksum</name>\n<value><string>ddcbe498ba465e53a82e340162d23e28</string></value>\n</member>\n<member>\n<name>profile_name</name>\n<value><string>172.22.40.46</string></value>\n</member>\n<member>\n<name>system_id</name>\n<value><string>ID-1013309576</string></value>\n</member>\n<member>\n<name>architecture</name>\n<value><string>i686-redhat-linux</string></value>\n</member>\n<member>\n<name>os_release</name>\n<value><string>5Server</string></value>\n</member>\n<member>\n<name>fields</name>\n<value><array><data>\n<value><string>system_id</string></value>\n<value><string>os_release</string></value>\n<value><string>operating_system</string></value>\n<value><string>architecture</string></value>\n<value><string>username</string></value>\n<value><string>type</string></value>\n</data></array></value>\n</member>\n<member>\n<name>type</name>\n<value><string>REAL</string></value>\n</member>\n</struct></value>\n</param>\n</params>\n',)
e: [('SSL routines', 'SSL3_GET_SERVER_CERTIFICATE', 'certificate verify failed')]
self: <up2date_client.rhnserver._DoCallWrapper object at 0x8cec8ec>
error: 'SSL routines', 'SSL3_GET_SERVER_CERTIFICATE', 'certificate verify failed'
pieces: ["'SSL routines'", " 'SSL3_GET_SERVER_CERTIFICATE'", " 'certificate verify failed'"]
kwargs: {}
message: certificate verify failed

Open in new window

0
Comment
Question by:dloszewski
6 Comments
 
LVL 13

Expert Comment

by:Daniel Helgenberger
ID: 39953470
I suppose it is RHEL 5 and you are using satellites?

https://access.redhat.com/site/solutions/93313
0
 

Author Comment

by:dloszewski
ID: 39953510
correct, unfortunately I'm not a subscriber so unable to see that posting
0
 
LVL 10

Expert Comment

by:tmoore1962
ID: 39954042
the ssl cert has expired.  Goggle how to configure YUM to not use ssl cert there was a write up for it as I had to do it just a little while ago but can't find notes on the file to edit so that it doesn't update using ssl connection.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 61

Expert Comment

by:gheist
ID: 39955226
Sadly if your subscriptin has expired you are not entitled to run your system anymore. Redhat Licence is readable without subscription...
0
 
LVL 13

Accepted Solution

by:
Daniel Helgenberger earned 500 total points
ID: 39955232
Sadly if your subscriptin has expired you are not entitled to run your system anymore. Redhat Licence is readable without subscription...

Hello Dave,
this is why I didn't help you any further, too.  If your subscription is expired, you cannot use the RHEL repos with or without satellites any more. Either renew your subscriptions or convert your installations to CentOS:
http://knowledgelayer.softlayer.com/procedure/convert-redhat-centos
0
 
LVL 61

Expert Comment

by:gheist
ID: 39955255
You can also convert to oracle linux http://public-yum.oracle.com/ (Especially good if you would like to have certified platform for their database...)
(Actually it is a minor patch that extends that certificate, and $ends a warning message IF you are a subscriber)
0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

Little introduction about CP: CP is a command on linux that use to copy files and folder from one location to another location. Example usage of CP as follow: cp /myfoder /pathto/destination/folder/ cp abc.tar.gz /pathto/destination/folder/ab…
SSH (Secure Shell) - Tips and Tricks As you all know SSH(Secure Shell) is a network protocol, which we use to access/transfer files securely between two networked devices. SSH was actually designed as a replacement for insecure protocols that sen…
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now