Active IQ Unified Manager Discussions

OCUM 7.0RC1 - cant add ONTAP 9 systems

thomasb82
9,246 Views

Hi, we have some 8.3.x cDOT clusters added in OCUM, all working fine.

 

But clusters with version 9 (GA) can't be added.

We get this error:

Cluster add failed. Failed to fetch the HTTPS certificate from *ontap9system*. Enter a valid Hostname or Port.

 

Certificates are not expired, credentials work fine.

 

Any ideas?

 

 

 

Quick update: It works with HTTP (Port 80) but of course we have security concerns so we need to use HTTPS like on the others.

 

Thanks!

7 REPLIES 7

yannb
9,206 Views

What does the following command say?

 

::> system services web show 

Are you adding with the name or the IP address? (try both)

thomasb82
9,190 Views

Hi,

 

here you go:

 

External Web Services: true
Status: online
HTTP Protocol Port: 80
HTTPS Protocol Port: 443
HTTP Enabled: true

 

 

Yes it tried both IP and Hostname, it only works with non-secure HTTP...

niels
9,136 Views

Hi,

 

this may be caused because the hostname listed in the certificate does not match the actual hostname / FQDN of the cluster.

This may happen in case DNS settings or cluster name are changed post cluster setup.

I also wouldn't exclude the cluster setup logic to have a flaw so that hostname/FQDN of the cluster and the certificate don't match.

 

Please try to re-create the SSL certificate according to this KB article:

 

https://kb.netapp.com/support/index?page=content&id=1014389&actp=search&viewlocale=en_US&searchid=1474277936105

 

Although the article is written explicitely for ONTAP 8.1 and 8.2/8.3, please follow those steps outlined for 8.2/8.3 for ONTAP 9. They should be identical.

 

Then try adding the cluster to OCUM.

 

Kind regards, Niels

 

------

If this post resolved your issue, please help others by selecting ACCEPT AS SOLUTION or adding a KUDO or both.

thomasb82
9,086 Views

There was no DNS / Name change.

Brand new cluster setup, no changes there.

 

New cert didn't help, I have opend a ticket. Lets see...

thomasb82
9,042 Views

Hi,

 

so the fix / workaround is to modify the hosts file of both OCUM and OCPM by adding the ontap 9 systems.

Although ping worked fine without the host entries, technician said its a bug.

Yogananda
6,220 Views

Hello All,

 

I am facing the same error in all the ONTAP versions(Failed to fetch the HTTPS certificate from the Cluster). And also i dont see seperate HOSTS file for the OCUM. Could you please help me to get that.

 

 

davieb1969
5,404 Views

Hi, did you ever resolve this issue? I've renewed certs, created a hosts file and removed any instances in the cluster to a previous install of OCUM.

 

Getting connection failed on both http and https.

 

Thanks 

Public