[Kea-users] Kea HA with self signed certs

CS cs.temp.mail at gmail.com
Wed Mar 13 21:11:11 UTC 2024


Hey guys,

What does this mean?
Failed to run: [SSL: TLSV13_ALERT_CERTIFICATE_REQUIRED] tlsv13 alert
certificate required (_ssl.c:2578)

I'm back again after getting pulled off onto other projects, I am working
on getting my small kea cluster running with Micetro.

Micetro refuses to add the servers and while I'd thought I had solved all
my problems with ya'll before (kea daemons appear to be running error free)
on re-approaching the problem I have notice I have not been able to get
kea-shell to run against either localhost or the other server.

My knowledge of creating and using SSL is very poor. For this project alone
I worked with the folks on reddit to develop a script for creating the self
signed certs.
https://www.reddit.com/r/openssl/comments/170r9ko/creating_self_signed_cert_for_kea_encryption/?utm_source=share&utm_medium=web2x&context=3
so I assume the error is somewhere there. But I don't understand the reply
when I run kea-shell.

kea-shell --host 10.111.45.45 --port 8000 --auth-user "bad username"
--auth-password "bad password" --ca certs/Certificate_Autority.pem
list-commands
Failed to run: [SSL: TLSV13_ALERT_CERTIFICATE_REQUIRED] tlsv13 alert
certificate required (_ssl.c:2578)

Do you all know what I've done wrong or what I need to do to make the cert
right?

CS, cs.Temp.Mail at gMail.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.isc.org/pipermail/kea-users/attachments/20240313/6f89b5b0/attachment.htm>


More information about the Kea-users mailing list