无法获得Koji Build系统的工作

时间:2014-02-06 08:48:53

标签: apache ssl centos6 koji

我按照文档(http://fedoraproject.org/wiki/Koji/ServerHowTo)的建议在 Centos6计算机服务器中设置 koji 构建环境。 我可以使用http正确访问Koji Web。但是,当切换到https:

时,我面临 SSL证书问题

Mozilla FireFOx产生的客户端浏览器错误:

SSL peer was unable to negotiate an acceptable set of security parameters. (Error code: ssl_error_handshake_failure_alert)
  • 启用了两个管理员用户后,运行命令时出现Koji secific错误:

    苏克曼; koji调用getLoggedInUser

错误:kojiman:

Error: [('SSL routines', 'SSL3_GET_SERVER_CERTIFICATE', 'certificate verify failed')]

su kojiadmin; koji调用getLoggedInUser 错误:kojiadmin

Error: [('SSL routines', 'SSL3_READ_BYTES', 'sslv3 alert bad certificate'), ('SSL routines', 'SSL3_WRITE_BYTES', 'ssl handshake failure')]

在httpd ssl log中,我有以下内容:

############################”

SSL错误:

[Wed Feb 05 18:37:28 2014] [error] [client 46.21.193.155] Certificate Verification: Error (19): self signed certificate in certificate chain
[Wed Feb 05 18:44:06 2014] [warn] RSA server certificate CommonName (CN) `kojihub' does NOT match server name!?
[Wed Feb 05 18:44:06 2014] [warn] RSA server certificate CommonName (CN) `kojihub' does NOT match server name!?
  • 当我测试我使用openSSL获得的证书时:

    openssl s_client -connect localhost:443 -tls1 -CAfile /etc/pki/koji/kojihub.pem

我确实得到了:

verify error:num=20:unable to get local issuer certificate
verify error:num=27:certificate not trusted
verify error:num=21:unable to verify the first certificate

verify return:1
139736479307592:error:14094410:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake failure:s3_pkt.c:1256:SSL alert number 40
139736479307592:error:1409E0E5:SSL routines:SSL3_WRITE_BYTES:ssl handshake failure:s3_pkt.c:596:
Verify return code: 21 (unable to verify the first certificate)

任何帮助将不胜感激!

1 个答案:

答案 0 :(得分:0)

解决。 是否使用错误的证书为主建设者。 改为kojid.conf