SSL certificate problem: unable to get local issuer certificate for
Hello everyone, I have update my centreon of the version 23 to 24. Since, i have this error "SSL certificate problem: unable to get local issuer certificate for" this error appears when I want to add a host
do you know this problem? How to fix it?
Page 1 / 1
Hello,
I have the exact same issue, but only while updating centreon from version 24.04.07 to 24.10.01.
When I try to create a new host (and only when I perform that operation), I have the following message :
My certificate is signed by a CA of my own (almost like described in that link) and my virtualhost looked like that :
So to add a new host I need to disable SSL on the Virtualhost and access to Centreon in plain text …
Do someone has a workaround ?
Thank you very much for your time.
Regards,
Thierry
I have the same issue. Any workaround?
I have the same issue.
Any solution ?
I have the same issue with the latest update 24.10.2
For information I have resolved this problem with add the certificate of the webserver Centreon in the CA Authority in RHEL, /etc/pki/tls/certs/ca-bundle.crt
I don’t know why but my certificate was in state “UNKNOWN: 500 Can't connect to (certificate verify failed)”, view with the command “curl -I https://websitecentreon”
I have the same issue with the latest update 24.10.2
@sibeasc : i add the information of the .crt in /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem and restart cbd/centengine/centreon/gorgoned/httpd but no change...
I don’t have need to restart gorgoned service. Dont’t you have the file ca-bundle.crt ?
+ vim /etc/pki/tls/openssl.cnf # Add the alt_names tag that allows you to inform our various IPs and FQDNs for the server / alt_names ] IP.1 = 192.168.36.2 DNS.1 = centreon.satish.com # If you have several IP (HA: vip + ip) # IP.2 = xxx.xxx.xxx.xxx / v3_ca ] subjectAltName = @alt_names
Generate New Certificate + openssl genrsa -out /etc/centreon/certificate/centreon.key 2048
Looks like a chain was extracted and added. Thank you @singh5816
Hello
I've been having the same problem since I migrated from 24.10 to OL8.10, but not with a self-signed certificate. In fact, I purchased one from Gandi. Is there a way to fix this without regenerating the certificate?
I had no problems with 23.04.
Best regards
@S.lhotellier there is this link that might help you for Gandi
I had no problem with centre 23.04 but now with 24.10, I need to asl my team to not connect in https because when we save config we lost it (for exemple input or output in broker conf).
Best regards
Hello I made a test to check certificte with testsslserver4.exe :
TestSSLServer4.exe **************************** Connection: *******************************:443 SNI: ************************************* TLSv1.0: server selection: enforce server preferences 3f- (key: RSA) ECDHE_RSA_WITH_AES_256_CBC_SHA 3f- (key: RSA) ECDHE_RSA_WITH_AES_128_CBC_SHA 3f- (key: RSA) DHE_RSA_WITH_AES_256_CBC_SHA 3f- (key: RSA) DHE_RSA_WITH_CAMELLIA_256_CBC_SHA 3f- (key: RSA) DHE_RSA_WITH_AES_128_CBC_SHA 3f- (key: RSA) DHE_RSA_WITH_SEED_CBC_SHA 3f- (key: RSA) DHE_RSA_WITH_CAMELLIA_128_CBC_SHA TLSv1.1: idem TLSv1.2: server selection: enforce server preferences 3f- (key: RSA) ECDHE_RSA_WITH_AES_256_GCM_SHA384 3f- (key: RSA) ECDHE_RSA_WITH_AES_128_GCM_SHA256 3f- (key: RSA) ECDHE_RSA_WITH_AES_256_CBC_SHA384 3f- (key: RSA) ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384 3f- (key: RSA) ECDHE_RSA_WITH_AES_128_CBC_SHA256 3f- (key: RSA) ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 3f- (key: RSA) ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 3f- (key: RSA) ECDHE_RSA_WITH_ARIA_256_GCM_SHA384 3f- (key: RSA) ECDHE_RSA_WITH_ARIA_128_GCM_SHA256 3f- (key: RSA) ECDHE_RSA_WITH_AES_256_CBC_SHA 3f- (key: RSA) ECDHE_RSA_WITH_AES_128_CBC_SHA 3f- (key: RSA) DHE_RSA_WITH_AES_256_GCM_SHA384 3f- (key: RSA) DHE_RSA_WITH_CHACHA20_POLY1305_SHA256 3f- (key: RSA) DHE_RSA_WITH_AES_256_CCM_8 3f- (key: RSA) DHE_RSA_WITH_AES_256_CCM 3f- (key: RSA) DHE_RSA_WITH_ARIA_256_GCM_SHA384 3f- (key: RSA) DHE_RSA_WITH_AES_128_GCM_SHA256 3f- (key: RSA) DHE_RSA_WITH_AES_128_CCM_8 3f- (key: RSA) DHE_RSA_WITH_AES_128_CCM 3f- (key: RSA) DHE_RSA_WITH_ARIA_128_GCM_SHA256 3f- (key: RSA) DHE_RSA_WITH_AES_256_CBC_SHA256 3f- (key: RSA) DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256 3f- (key: RSA) DHE_RSA_WITH_AES_128_CBC_SHA256 3f- (key: RSA) DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 3f- (key: RSA) DHE_RSA_WITH_AES_256_CBC_SHA 3f- (key: RSA) DHE_RSA_WITH_CAMELLIA_256_CBC_SHA 3f- (key: RSA) DHE_RSA_WITH_AES_128_CBC_SHA 3f- (key: RSA) DHE_RSA_WITH_SEED_CBC_SHA 3f- (key: RSA) DHE_RSA_WITH_CAMELLIA_128_CBC_SHA ========================================= +++++ SSLv3/TLS: 1 certificate chain(s) +++ chain: length=2 names match: no includes root: no signature hash(es): SHA-256 SHA-384 + certificate order: 0 thumprint: ************************************ serial: ***************************** subject: CN=fsyprodcentcentral.syleps.fr issuer: CN=GandiCert,O=Gandi SAS,C=FR valid from: 2025-03-13 00:00:00 UTC valid to: 2026-02-28 23:59:59 UTC key type: RSA key size: 4096 sign hash: SHA-256 server names: *************************** + certificate order: 1 thumprint: **************************************** serial: ********************************** subject: CN=Gandi Standard SSL CA 2,O=Gandi,L=Paris,ST=Paris,C=FR issuer: CN=USERTrust RSA Certification Authority,O=The USERTRUST Network,L=Jersey City,ST=New Jersey,C=US valid from: 2014-09-12 00:00:00 UTC valid to: 2024-09-11 23:59:59 UTC key type: RSA key size: 2048 sign hash: SHA-384 ========================================= Server compression support: no Server sends a random system time. Secure renegotiation support: yes Encrypt-then-MAC support (RFC 7366): yes SSLv2 ClientHello format (for SSLv3+): yes Minimum DH size: 4096 DH parameter reuse: no Minimum EC size (with extension): 252 Server does not use EC without the client extension ECDH parameter reuse: no Supported curves (size and name) ('*' = selected by server): 256 secp256r1 (P-256) 384 secp384r1 (P-384) 521 secp521r1 (P-521) 252 ecdh_x25519 446 ecdh_x448 ========================================= No warning.
there is no error, no warning but I still have the problem
I have no problem to access centreon, my problem is only when validating changes : I loose all data from the page I leave, for exemple in broker management page all the input or output parameters.