Yum commands and registration to Red Hat Satellite or Capsule fail due to SSL-related errors.
Issue
- Registration to Red Hat Satellite or Red Hat Capsule is failing with certificate key usage inadequate for attempted operation.
- Where to look if there is an issue with
SSLcertificates or connectivity overHTTPSwith Red Hat SatelliteorRed Hat Capsule`? - How to verify and troubleshoot whether the
SSLcertificate installed on the Client systems are matching withRed Hat satelliteorRed Hat Capsule? - When registering systems to
Red Hat Satellite/Capsuleusingsubscription-managerfails with Unable to verify server's identity: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:897) . -
After updating custom
SSL certificateson the Satellite and the Capsule,subscription-managerfails with the below error.Unable to verify server's identity: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:618) -
After updating custom SSL certificates on
Red Hat Satellite6, the dnf commands issued from content hosts are encountering the following errors:- Curl error (60): Peer certificate cannot be authenticated with given CA certificates for https://satellitetest.example.com/pulp/repos/Test/Library/content/dist/rhel8/8/x86_64/appstream/os/repodata/repomd.xml [SSL certificate problem: self signed certificate in certificate chain] Error: Failed to download metadata for repo 'rhel-8-for-x86_64-appstream-rpms': Cannot download repomd.xml: Cannot download repodata/repomd.xml: All mirrors were tried- Curl error (60): Peer certificate cannot be authenticated with given CA certificates for https://capsule.example.com/pulp/content/organization/Library/content/dist/rhel8/8/x86_64/appstream/os/repodata/repomd.xml [SSL certificate problem: unable to get local issuer certificate]
Environment
- Red Hat Satellite 6
- Red Hat Capsule 6
- Custom SSL Certificates
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.