Files
doc-exports/docs/mrs/umn/ALM-24012.html
Yang, Tong 2195db241c MRS UMN 20231220 version update
Reviewed-by: Pruthi, Vineet <vineet.pruthi@t-systems.com>
Reviewed-by: Rechenburg, Matthias <matthias.rechenburg@t-systems.com>
Co-authored-by: Yang, Tong <yangtong2@huawei.com>
Co-committed-by: Yang, Tong <yangtong2@huawei.com>
2024-05-16 09:40:21 +00:00

91 lines
11 KiB
HTML

<a name="ALM-24012"></a><a name="ALM-24012"></a>
<h1 class="topictitle1">ALM-24012 Flume Certificate File Has Expired</h1>
<div id="body0000001213828236"><p id="ALM-24012__p1435536171511">This section applies to MRS 3.2.0<span id="ALM-24012__ph174355293719">-LTS.2</span> or later.</p>
<div class="section" id="ALM-24012__section238231914117"><h4 class="sectiontitle">Description</h4><p id="ALM-24012__p5166194361117">Flume checks whether its certificate file in the system has expired every hour. This alarm is generated when the server certificate has expired. This alarm is automatically cleared when the certificate file becomes valid again.</p>
</div>
<div class="section" id="ALM-24012__section10101081213"><h4 class="sectiontitle">Attribute</h4>
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="ALM-24012__table33817547" frame="border" border="1" rules="all"><thead align="left"><tr id="ALM-24012__row8931076"><th align="left" class="cellrowborder" valign="top" width="33.33333333333333%" id="mcps1.3.3.2.1.4.1.1"><p id="ALM-24012__p52328576">Alarm ID</p>
</th>
<th align="left" class="cellrowborder" valign="top" width="33.33333333333333%" id="mcps1.3.3.2.1.4.1.2"><p id="ALM-24012__p10756297">Alarm Severity</p>
</th>
<th align="left" class="cellrowborder" valign="top" width="33.33333333333333%" id="mcps1.3.3.2.1.4.1.3"><p id="ALM-24012__p65953734">Auto Clear</p>
</th>
</tr>
</thead>
<tbody><tr id="ALM-24012__row40652256"><td class="cellrowborder" valign="top" width="33.33333333333333%" headers="mcps1.3.3.2.1.4.1.1 "><p id="ALM-24012__p4498430">24012</p>
</td>
<td class="cellrowborder" valign="top" width="33.33333333333333%" headers="mcps1.3.3.2.1.4.1.2 "><p id="ALM-24012__p28828553">Major</p>
</td>
<td class="cellrowborder" valign="top" width="33.33333333333333%" headers="mcps1.3.3.2.1.4.1.3 "><p id="ALM-24012__p53411432">Yes</p>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="section" id="ALM-24012__section15483537"><h4 class="sectiontitle">Parameters</h4>
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="ALM-24012__table31358724" frame="border" border="1" rules="all"><thead align="left"><tr id="ALM-24012__row33518103"><th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.4.2.1.3.1.1"><p id="ALM-24012__p30611809">Name</p>
</th>
<th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.4.2.1.3.1.2"><p id="ALM-24012__p63637484">Meaning</p>
</th>
</tr>
</thead>
<tbody><tr id="ALM-24012__row163311621185116"><td class="cellrowborder" valign="top" width="50%" headers="mcps1.3.4.2.1.3.1.1 "><p id="ALM-24012__p17935380415">Source</p>
</td>
<td class="cellrowborder" valign="top" width="50%" headers="mcps1.3.4.2.1.3.1.2 "><p id="ALM-24012__p187931338134115">Specifies the cluster for which the alarm is generated.</p>
</td>
</tr>
<tr id="ALM-24012__row54362592"><td class="cellrowborder" valign="top" width="50%" headers="mcps1.3.4.2.1.3.1.1 "><p id="ALM-24012__p41293795">ServiceName</p>
</td>
<td class="cellrowborder" valign="top" width="50%" headers="mcps1.3.4.2.1.3.1.2 "><p id="ALM-24012__p56463136">Specifies the service for which the alarm is generated.</p>
</td>
</tr>
<tr id="ALM-24012__row38406179"><td class="cellrowborder" valign="top" width="50%" headers="mcps1.3.4.2.1.3.1.1 "><p id="ALM-24012__p23892775">RoleName</p>
</td>
<td class="cellrowborder" valign="top" width="50%" headers="mcps1.3.4.2.1.3.1.2 "><p id="ALM-24012__p56266616">Specifies the role for which the alarm is generated.</p>
</td>
</tr>
<tr id="ALM-24012__row36637496"><td class="cellrowborder" valign="top" width="50%" headers="mcps1.3.4.2.1.3.1.1 "><p id="ALM-24012__p14847206">HostName</p>
</td>
<td class="cellrowborder" valign="top" width="50%" headers="mcps1.3.4.2.1.3.1.2 "><p id="ALM-24012__p61773077">Specifies the host for which the alarm is generated.</p>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="section" id="ALM-24012__section722973311121"><h4 class="sectiontitle">Impact on the System</h4><p id="ALM-24012__p1068283611125">The Flume client cannot access the Flume server.</p>
</div>
<div class="section" id="ALM-24012__section46207013"><h4 class="sectiontitle">Possible Causes</h4><p id="ALM-24012__p62452010">The Flume certificate file has expired.</p>
</div>
<div class="section" id="ALM-24012__section1932086181519"><h4 class="sectiontitle">Procedure</h4><p id="ALM-24012__p9765201181513"><strong id="ALM-24012__b4400121914158">View alarm information.</strong></p>
<ol id="ALM-24012__ol97206444148"><li id="ALM-24012__li11839825144718"><span>Log in to <span id="ALM-24012__text34789336432">MRS</span> Manager and choose <strong id="ALM-24012__b1833205014416">O&amp;M</strong>. In the navigation pane on the left, choose <strong id="ALM-24012__b11341175024418">Alarm</strong> &gt; <strong id="ALM-24012__b6343750124414">Alarms</strong>. On the page that is displayed, locate the row containing <strong id="ALM-24012__b113451050114420">ALM-24012 Flume Certificate Has Expired</strong>, and view the <strong id="ALM-24012__b1834510500448">Location</strong> information. View the IP address of the instance for which the alarm is generated.</span></li></ol>
<p id="ALM-24012__p72121810184"><strong id="ALM-24012__b1239068195917">Check whether the certificate file in the system is valid. If it is not, generate a new one.</strong></p>
<ol start="2" id="ALM-24012__ol093713227375"><li id="ALM-24012__li39371222113715"><span>Log in to the node for which the alarm is generated as user <strong id="ALM-24012__b159333124511">root</strong> and run the <strong id="ALM-24012__b8601533134510">su - omm</strong> command to switch to user <strong id="ALM-24012__b462203394517">omm</strong>.</span></li><li id="ALM-24012__li177615231184"><span>Run the following command to go to the Flume service certificate directory:</span><p><p id="ALM-24012__p1575415235811"><strong id="ALM-24012__b11649760539">cd ${BIGDATA_HOME}/FusionInsight_Porter_*/install/FusionInsight-Flume-*/flume/conf</strong></p>
</p></li><li id="ALM-24012__li8235154418819"><span>Run the following command to check the effective time and expiration time of the HA user certificate to determine whether the certificate file is still in the validity period:</span><p><div class="p" id="ALM-24012__p19184174518813"><strong id="ALM-24012__b1512574317516">openssl x509 -noout -text -in flume_sChat.crt</strong><ul id="ALM-24012__ul6937722163711"><li id="ALM-24012__li10937142203720">If yes, go to <a href="#ALM-24012__li593632253716">9</a>.</li><li id="ALM-24012__li8937222183720">If no, go to <a href="#ALM-24012__li161213411093">5</a>.</li></ul>
</div>
</p></li><li id="ALM-24012__li161213411093"><a name="ALM-24012__li161213411093"></a><a name="li161213411093"></a><span>Run the following command to go to the Flume script directory:</span><p><p id="ALM-24012__p1369012421997"><strong id="ALM-24012__b10153103102710">cd ${BIGDATA_HOME}/FusionInsight_Porter_*/install/FusionInsight-Flume-*/flume/bin</strong></p>
</p></li><li id="ALM-24012__li084616591915"><a name="ALM-24012__li084616591915"></a><a name="li084616591915"></a><span>Run the following command to generate a new certificate file. Then check whether the alarm is automatically cleared one hour later.</span><p><div class="p" id="ALM-24012__p2628170131016"><strong id="ALM-24012__b57614165395">sh geneJKS.sh -f </strong><em id="ALM-24012__i16486142733915">Custom certificate password of the Flume role on the server</em> <strong id="ALM-24012__b123841740143914">-g </strong><em id="ALM-24012__i57281049113911">Custom certificate password of the Flume role on the client</em><ul id="ALM-24012__ul770182010388"><li id="ALM-24012__li127011820153816">If yes, go to <a href="#ALM-24012__li1788491915716">8</a>.</li><li id="ALM-24012__li1465218563614">If no, go to <a href="#ALM-24012__li172496117507">7</a>.<div class="note" id="ALM-24012__note17847172210279"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><div class="p" id="ALM-24012__p136902296299">The custom certificate passwords must meet the following complexity requirements:<ul id="ALM-24012__ul663011436283"><li id="ALM-24012__li17630154392816">Contain at least four types of uppercase letters, lowercase letters, digits, and special characters.</li><li id="ALM-24012__li10630104362812">Contain 8 to 64 characters.</li><li id="ALM-24012__li063084316285">Be changed periodically (for example, every three months), and certificates and trust lists are generated again to ensure security.</li></ul>
</div>
</div></div>
</li></ul>
</div>
</p></li><li id="ALM-24012__li172496117507"><a name="ALM-24012__li172496117507"></a><a name="li172496117507"></a><span>Log in to the Flume node for which the alarm is generated as user <strong id="ALM-24012__b20345547174710">omm</strong> and repeat <a href="#ALM-24012__li161213411093">5</a> to <a href="#ALM-24012__li084616591915">6</a>. Then, check whether the alarm is automatically cleared one hour later.</span><p><ul id="ALM-24012__ul567911341584"><li id="ALM-24012__li467933412817">If yes, go to <a href="#ALM-24012__li1788491915716">8</a>.</li><li id="ALM-24012__li96791534282">If no, go to <a href="#ALM-24012__li593632253716">9</a>.</li></ul>
</p></li><li id="ALM-24012__li1788491915716"><a name="ALM-24012__li1788491915716"></a><a name="li1788491915716"></a><span>Check whether this alarm is generated again during periodic system check.</span><p><ul id="ALM-24012__ul13890131919711"><li id="ALM-24012__li188909195714">If yes, go to <a href="#ALM-24012__li593632253716">9</a>.</li><li id="ALM-24012__li18904191779">If no, no further action is required.</li></ul>
</p></li></ol>
<p class="tableheading" id="ALM-24012__p3538354385459"><strong id="ALM-24012__b6160463585522">Collect the fault information.</strong></p>
<ol start="9" id="ALM-24012__ol093762283713"><li id="ALM-24012__li593632253716"><a name="ALM-24012__li593632253716"></a><a name="li593632253716"></a><span>On <span id="ALM-24012__text17843171191310">MRS</span> Manager, choose <strong id="ALM-24012__b1319622854812">O&amp;M</strong>. In the navigation pane on the left, choose <strong id="ALM-24012__b12197122864810">Log</strong> &gt; <strong id="ALM-24012__b191981228194816">Download</strong>.</span></li><li id="ALM-24012__li99361822103719"><span>Expand the <strong id="ALM-24012__b1754619567214">Service</strong> drop-down list, and select <strong id="ALM-24012__b10546756221">Flume</strong> for the target cluster.</span></li><li id="ALM-24012__li293692216373"><span>Click <span><img id="ALM-24012__image13936322143711" src="en-us_image_0000001583127261.png"></span> in the upper right corner, and set <strong id="ALM-24012__b569917333488">Start Date</strong> and <strong id="ALM-24012__b207001333134819">End Date</strong> for log collection to 10 minutes ahead of and after the alarm generation time, respectively. Then, click <strong id="ALM-24012__b6701833204812">Download</strong>.</span></li><li id="ALM-24012__li1993762233711"><span>Contact <span id="ALM-24012__text7888164154819">O&amp;M personnel</span> and provide the collected logs.</span></li></ol>
</div>
<div class="section" id="ALM-24012__section169311343318"><h4 class="sectiontitle">Alarm Clearing</h4><p id="ALM-24012__p754913417333">This alarm is automatically cleared after the fault is rectified.</p>
</div>
<div class="section" id="ALM-24012__section53362350"><h4 class="sectiontitle">Related Information</h4><p id="ALM-24012__p7522741">None</p>
</div>
</div>
<div>
<div class="familylinks">
<div class="parentlink"><strong>Parent topic:</strong> <a href="mrs_01_1298.html">Alarm Reference (Applicable to MRS 3.x)</a></div>
</div>
</div>