CRS error when connect to DP clients from DP manager after turning on encryption

Hi!

 

I have DP 8.00 with recent patches (DPUXBDL_00801) running on my HP-UX server. I recently turned on encryption on cell manager and all the clients connected to it using omnicc utility to turn on encryption.

 

I have DP Manager 8.00 built 596 and it runs on Win 2008 platform.

 

When I am trying to connect to connect to DP server from DP Manager I am getting CRS errors and can not connect.

 

HP can start and stay up successfully on hp-ux platform without issues.

 

Why can't client connect and what can be done to fix client connect failure issue?

 

Thanks

 

 

Tags:

Parents
  • When you say 'DP Manager', are you talking about the GUI running on a Windows system?

  • Hi Bob!

    I modified to see if turning off will change the status, but it did not, here is what they look like:

     

     

    /etc/opt/omni/client/config file and changed value to enabled=0;

     

    /etc/opt/omni/server/config file and changed value to enabled=0

     

    /etc/opt/omni/server/cell/cell_info and changed the value to enabled 0

     

    CONFIG FILE

    ___________

     

    Full_Server_Name={

                encryption={

                            enabled=0;

                            trusted_certificates_file='/etc/opt/omni/client/certificates/hpdpcert.pem';

                            certificate_chain_file='/etc/opt/omni/client/certificates/hpdpcert.pem';

                            private_key_file='/etc/opt/omni/client/certificates/hpdpcert.pem';

                            pkcs12_keystore_filename='/etc/opt/omni/client/certificates/hpdpcert.p12';

                            pkcs12_keystore_password='hpdpcert';

                            pkcs12_ca_certificate_filename='/etc/opt/omni/client/certificates/hpdpcert.p12';

                            pkcs12_ca_certificate_password='hpdpcert';

                            pkcs12_private_key_filename='/etc/opt/omni/client/certificates/hpdpcert.p12';

                            pkcs12_private_key_password='hpdpcert';

                };

     

    CLIENT CONFIG FILE

    ____________

    encryption={

                enabled=0;

                trusted_certificates_file='/etc/opt/omni/client/certificates/hpdpcert.pem';

                certificate_chain_file='/etc/opt/omni/client/certificates/hpdpcert.pem';

                private_key_file='/etc/opt/omni/client/certificates/hpdpcert.pem';

                pkcs12_keystore_filename='/etc/opt/omni/client/certificates/hpdpcert.p12';

                pkcs12_keystore_password='hpdpcert';

                pkcs12_ca_certificate_filename='/etc/opt/omni/client/certificates/hpdpcert.p12';

                pkcs12_ca_certificate_password='hpdpcert';

                pkcs12_private_key_filename='/etc/opt/omni/client/certificates/hpdpcert.p12';

                pkcs12_private_key_password='hpdpcert';

    };

     

    CELL INFOFile

    -host "Full CLIENT1 Name" -os "hp ia64 hp-ux-11.31" -encryption 0 -core A.08.00 -cs A.08.00 -da A.08.00 -ma A.08.00 -cc A.08.00 -docs A.08.00 -ts_core A.08.00 -ts_cs A.08.00 -ts_as A.08.00 -ws A.08.00 -ts_jre A.08.00 -jce_dispatcher A.08.00 -jce_serviceregistry A.08.00 -host "Full CLIENT2 Name" -os "hp ia64 hp-ux-11.31" -encryption 0 -core A.08.00 -da A.08.00 -ma A.08.00 -ts_core A.08.00 -host "Full Server3 Name" -os "hp ia64 hp-ux-11.31" -encryption 0 -core A.08.00 -da A.08.00 -ma A.08.00 -ts_core A.08.00 -host "Full CLIENT3 Name" -os "hp ia64 hp-ux-11.31" -encryption 0 -core A.08.00 -da A.08.00 -ma A.08.00 -ts_core A.08.00 -host "Full CLIENT4 Name" -os "hp ia64 hp-ux-11.31" -core A.08.00 -da A.08.00 -ma A.08.00 -ts_core A.08.00 -encryption 0

  • Verified Answer

    One of my suggestions was going to be to turn off encryption to see if it fails the same way, to try and track what may be causing this problem

     

    Step 1. On the Cell Manager:
     
    • Remove/Rename the "config" file from the <DP_CONFIG>/clients
    • Remove/Rename the "config" file from the <DP_CONFIG>/server
    • Remove "-encryption 1" from <DP_CONFIG>/server /cell/cell_info file
     
    Step 2. On ALL DP clients:
     
    • Remove/Rename the "config" file from the <DP_CONFIG>/clients
  • Hi Bob!

     

    Removal worked fine. Now, how do I turn encryption on correctly? My setup has DP 8.0 cell mgr running on hp-ux and DP client is Win 2008 to manage data protector. After turning encryption on, DP client on Win 2008 fails to connect (CRS errors) with DP server 8.0 running on hp-ux.

     

    Any advice?

     

    Thanks

Reply Children
No Data