09-30-2014 02:42 PM - edited 03-19-2019 08:40 AM
Getting these errors in the VCS Control log. information has been changed to protect the innocent.
All ports are allowed between the Control and Express.
The TLS Zone between the two show as active.
What is the cause of this issue?
2014-09-30T14:24:43-07:00 | portforwarding: Level="ERROR" Detail="Client control socket open failed" forwarding="localhost:8191:localhost:8192" host="vcse01.abc.com" id="31e6ca07-48e8-11e4-a492-0010f31ed774" retcode="255" err="ssh_x509store_cb: subject='C=US,...', error 20 at 0 depth lookup:unable to get local issuer certificate ssh_verify_cert: verify error, code=20, msg='unable to get local issuer certificate' key_verify failed for server_host_key " UTCTime="2014-09-30 21:24:43,537" |
2014-09-30T14:24:43-07:00 | ssh: Event="sshd" Module="openssh" Level="INFO" Detail="RSA+cert host key for IP address 'xxx.xxx.xxx.xxx' not in list of known hosts." UTCTime="2014-09-30 21:24:43" |
09-30-2014 06:08 PM
What kind of zone is this? Traversal? Do you have TLS verify? Basically its complaining that the peer address that is configured is not present in the certificate that is being presented. I would change the peer address to be a FQDN and the subject verify name to be the same FQDN.
09-30-2014 06:23 PM
It is a Unified Communications traversal between VCSC and VCSE.
I was using the host name instead of the cluster name in the zone. I changed it, because I believe the cluster name is in the certificate. But still getting the error.
06-08-2015 03:31 AM
hi John,
Is it fixed?
02-16-2017 04:00 AM
Hey John, Did you ever get this resolved? Im seeing the same error.
06-25-2020 02:27 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide