Horizon DAAS SP指纹与rm,ta认证失败

Horizon DAAS SP指纹与rm,ta认证失败,第1张

Horizon DAAS SP指纹与rm,ta认证失败 一、问题描述

某资源池SP设备与rm通信异常,rm状态和sp状态频繁闪断,设备间通信异常,导致租户资源分配报内部错误。SP设备状态如下:

二、分析处理

1)SP1上执行ssh到其他设备报如下类似错误:

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that a host key has just been changed.
The fingerprint for the ECDSA key sent by the remote host is
aa:aa:aa:aa:aa:aa:aa:aa:aa:aa:aa:aa:aa:aa:aa:aa.
Please contact your system administrator.
Add correct host key in /home/hicode/.ssh/known_hosts to get rid of this message.
Offending ECDSA key in /home/hicode/.ssh/known_hosts:28
  remove with: ssh-keygen -f "/home/hicode/.ssh/known_hosts" -R ip.ip.ip.ip
ECDSA host key for ip.ip.ip.ip has changed and you have requested strict checking.
Host key verification failed

本机执行 sudo ssh-keygen -f “/root/.ssh/known_hosts” -R 远程主机 //清除远程主机的公钥

2)

注: ssh-copy-id 将key写到远程机器的 ~/ .ssh/authorized_key.文件中
3)

4)




上图可见0.3指向到rm01;实际rm01地址应该是0.4;

但实际检查rm01确实是0.4:

将rm1关机后,两边都断开了:

于是重置rm01;

三、附录:ssh认证

1)ssh公钥,私钥生成

本地机器上执行ssh-keygen产生公钥私钥对。

验证:cat .ssh/id_rsa.pub //公钥内容如下所示,后续写入 ~/ .ssh/authorized_key和 ~/ .ssh/know_hosts文件

ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCl9N5+xboqSIagBx02rdZ2fkROCPW8iW7hl6Gu+2hkBYYy/b1qcOm8RF/AMyas3i0QEK7Hcu9H51l2lulVbS5n9M9FaWIyYzssaS012x2mg9iA6MxPMlaXFsZ5jnVrGicndzf3VUu9kCErp5q0OzzMjsG3PKQevzWZJSBaFgc8NF5ZJ+VT54BN8ktMTHVwOo15I2Uai+bs4eP0NsuwIJmGyYIUOuvTuUtJxGV3hZ+tcjhupupqVCwYOE+cDz8VkFBGtnKsdE69hWoY2VUfEOAfHZptra7Ce9dXfDgx9jxuuNiJYtGo/bZDfe+UJ5HUv8wrL+hFeRIihdmP2CKJD8j5 azdebug_it@azdebug_it

2)用ssh-copy-id将公钥复制到远程机器中

eg: ssh-copy-id -i .ssh/id_rsa.pub desktone@192.168.16.3 //[-i [identity_file]],指定认证文件

欢迎分享,转载请注明来源:内存溢出

原文地址: http://outofmemory.cn/zaji/5071114.html

(0)
打赏 微信扫一扫 微信扫一扫 支付宝扫一扫 支付宝扫一扫
上一篇 2022-11-16
下一篇 2022-11-16

发表评论

登录后才能评论

评论列表(0条)

保存