"Error [ERR_TL S_CERT_ALTNAME_INVALID]: Hostname/IP Does not Match Certificate's altnames:" Which Breaks the Communication to Management Plane from Node.

Problem

  • Comms not able to communicate to management plane and throwing the following error.
Comms Log
Copy

Environment

  • Platform9 Edge Cloud - v-5.3.0-2075501

Cause

  • Host agent config file is not updated with the cert_version parameter which leads comms to use an older cert version.
hostagent.conf
Copy
  • From error message [2023-09-03 14:29:35.144] [ERROR] sni-broker.v0.mgplane.pf9.localnet-::1-5672-4 - TLS socket for client 28180 error.The sni-broker.v0 indicates it is referring to cert version v0.

Resolution

  • Identify the latest cert_version.
certs directory
Copy
  • Update the hostagent.conf file
hostagent.conf
Copy
  • Restart the services.
restart services
Copy

##

Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard