Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

CPPM 6.8.1 db query error

This thread has been viewed 16 times
  • 1.  CPPM 6.8.1 db query error

    Posted Jun 21, 2019 04:27 AM
      |   view attached

    Just upgraded our building (dev) servers to cppm 6.8.1. I'm running a 2 node cluster

     

    While everythnig seems to work, I've noticed that whenever I try and access Access-Tracker records for the slave publisher I get a db connection error. See attached file

     

    Everything worked in 6.8.0 and does work in 6.8.0 as thats what our production cluster is using

     

    During the . upgrade I did notice some warning/error messages about ensuring tht the clearpass cert contained server IP addresses in the SAN field... we don't have these. Might this affect the master publisher extracting info from a cluster member ? 

     

     



  • 2.  RE: CPPM 6.8.1 db query error

    Posted Jun 21, 2019 06:29 AM

    We tried to reproduce the issue in internal testbeds. But we are not seeing the issue you mentioned  . Did you follow any specific steps to see this issue?



  • 3.  RE: CPPM 6.8.1 db query error

    Posted Jun 21, 2019 06:37 AM

    Nope, 

     

    just logged onto the master publisher, went to access tracker and clicked on entry from non master publisher cluster member. Still doing it now if you want to remote session to it

     



  • 4.  RE: CPPM 6.8.1 db query error

    Posted Jun 21, 2019 06:40 AM

    Everything else is working ... 



  • 5.  RE: CPPM 6.8.1 db query error

    EMPLOYEE
    Posted Jun 21, 2019 09:54 PM
    Happening here too. Investigating for more details.


  • 6.  RE: CPPM 6.8.1 db query error

    EMPLOYEE
    Posted Jun 22, 2019 08:07 PM

    I just fixed this by regenerating new DB Server Certificates with all the IP addresses of every Policy Manager node in my cluster, and rebooted. Everything works fine now. 



  • 7.  RE: CPPM 6.8.1 db query error

    Posted Jun 24, 2019 03:23 AM

    o.k. thought everyrthing was o.k. here because of the following in the release notes

     

     

    When ClearPass is updated from 6.8.0 to 6.8.x, the default self-signed database server certificate is automatically regenerated and will be valid for five years instead of one year. Similarly, in future when a 6.8.x system is upgraded to a major version, a new default self-signed database server certificate with a five-year validity will be generated. This change only affects the default database server certificate; any Certificate Authority (CA) signed database certificate you might have created is not replaced. (CP‑33732)

    But obviously not, so how do I recreate the db server cert? is  that the same as the https cert ?



  • 8.  RE: CPPM 6.8.1 db query error

    Posted Jun 24, 2019 03:30 AM

    o.k. found it, so this can just be a locally generated certificate then ?



  • 9.  RE: CPPM 6.8.1 db query error

    EMPLOYEE
    Posted Jun 24, 2019 03:36 AM
    Yes


  • 10.  RE: CPPM 6.8.1 db query error

    Posted Jun 24, 2019 03:43 AM

    one final ( probably silly)  question, each self generated cert only has the IP addresss associated with that server in the SAN and not all the ip addresses in a cluster ?

    A



  • 11.  RE: CPPM 6.8.1 db query error

    EMPLOYEE
    Posted Jun 24, 2019 04:04 AM

    I’m not positive but I would include the IP to be safe. I know the IP needs to be in the San field of HTTPS cert for DUR



  • 12.  RE: CPPM 6.8.1 db query error

    Posted Jun 24, 2019 04:15 AM

    o.k. so I'll put all the IP addresses of cluster members in the san field.

     

    >

    >I know the IP needs to be in the San field of radius cert for DUR

    >

     

    Really? is there a manual entry for that?

     

    Note:- Yes found that entry, hence the questipn about all the IP addresses in a cluster or just the IP addresses associated with a single member of the cluster

     

    I'm doing downloadable user profiles at the moment and they don't need the SAN to have IP addresses in the HTTPS cert.

     

    The reason I ask i that DUR are next on the list to try out and

    We  run 2 clearpass clusters both with the same HTTPS cert ( production and building(dev)). The prodn one has 6 nodes some of which have 2 ip addresses. If I need to specify all IP addresses associated with all clearpass cluster members the cet is going to be ijnstalled on ... that's a lot of SAN entries for a HTTPS cert if you;re adding cluster node names as well

     



  • 13.  RE: CPPM 6.8.1 db query error

    EMPLOYEE
    Posted Jun 24, 2019 04:27 AM
    I typed radius instead of https. I just updated my post just before you posted...lol. Did some testing the other day and on self signed and I needed to put IP in the SAN. I might be wrong on the requirement but since I was not using FDQN I put the ip in San. It’s late here but I can test in the morning


  • 14.  RE: CPPM 6.8.1 db query error

    Posted Jun 24, 2019 04:28 AM

    :-)

    Database cert is the important one at the moment. DUR is for another day but any tests you could do would be much appreciated

    Rgds

    Alex

     



  • 15.  RE: CPPM 6.8.1 db query error

    Posted Jun 24, 2019 08:52 AM

    o.k. Finally got things working.

    Firstly I tried  generating a cert with SAN entries of the form IP:<cppm1>,IP:<cppm2>.... etc.  did this over the whole cluster and rebooted them all.

     

    This worked from the point of view that in Access Tracker I could view all entries from every cluster member ( 2 in this case). The problem was that although this bit did. work, replication didn't  so so I started seeing replication errors in the event log. If left unchecked I guess my cluster members would have dropped out of the cluster

     

    I then changed the SAN entry to be of the form DNS:<cppm1>,DNS:<cppm 2> ...... and rebooted them all

    And this time not only did Access-Tracker work but so did replication.

     

    Final tidy up increasing the cert lifetime to 5 years and that's it sorted.

     

    At some point I'll do our production cluster , but that'll require a SAN statement with 10 IP addresses

     

    Thanks to jpearcy00 for his comments



  • 16.  RE: CPPM 6.8.1 db query error

    EMPLOYEE
    Posted Jun 24, 2019 11:50 AM
    Yeah sorry for lack of details before. I was mobile. Same for me IP:<IP Address> fixed Access Tracker but cluster replication was still hosed. DNS:<IP Address> was the key for me as well.


  • 17.  RE: CPPM 6.8.1 db query error

    Posted Jun 24, 2019 11:51 AM

    Not a problem, got there in the end :-)

     

     



  • 18.  RE: CPPM 6.8.1 db query error

    EMPLOYEE
    Posted Jun 24, 2019 04:06 AM
    Just found this in the help

    Enter the alternative name for the specified Common Name. This field is optional. Enter the Subject Alternate Name in one of the following formats:
    email: email_address
    URI: URI
    IP: IP_address
    dns: DNS_name or IP_address
    rid: ID
    NOTE: When configuring a Database Server Certificate, either the Common Name or the Subject Alternate Name (SAN) DNS name must be set to the IP address (also, both fields can be set to the IP address if desired).