Friday, 2019-04-05

*** zigo has quit IRC22:01
*** FracKen has quit IRC22:01
*** FracKen has joined #openstack-ec2api22:02
*** Giorgis has joined #openstack-ec2api22:36
Giorgishello! I am trying to setup ec2-api with ssl on rocky and no matter what I do I am getting the following error in the logs22:40
Giorgisec2-api: SSLError: [SSL: SSL_HANDSHAKE_FAILURE] ssl handshake failure (_ssl.c:1822)22:40
Giorgisthe full trace can be found here: https://pastebin.com/iPHXudag (where I have hidden the hostname)22:40
Giorgiscan you help me please?22:40
GiorgisI have restarted all ec2 services both the openstack-ec2-api-metadata.service openstack-ec2-api.service and HTTPD22:52
Giorgisin ec2api.conf I have the ca_file, cert_file and key_file pointing to the same files that Openstack's Dashboard is using which can be accessed without a problem22:53
Giorgisusing openssl cli I am getting the error: SSL_connect:SSLv3 write client key exchange A write to 0x26c3e30 [0x2721290] (6 bytes => -1 (0xFFFFFFFFFFFFFFFF)) SSL_connect:error in SSLv3 write finished A SSL_connect:error in SSLv3 write finished A write:errno=3222:53
Giorgiswhen trying to connect to port 878822:53
Giorgisusing the same openssl cli for port 443 (dashboard) works out of the box without a problem22:53
Giorgisobviously the cert is not served properly but cannot figure out why...22:54
GiorgisI have send a relevant email at Openstack's discuss mailing list so if you could please be kind and check it...23:46
GiorgisThank you!!!23:46
*** Giorgis has left #openstack-ec2api23:46

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!