Ad Widget

Collapse

Random ssl errors after configuring PSK encryption

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • mcflurry
    Member
    • Jun 2022
    • 32

    #1

    Random ssl errors after configuring PSK encryption

    I got these random errors after restarting zabbix-agent2 on linux machines.

    2022/07/05 09:16:07.003936 Zabbix Agent2 hostname: [server.domain.com]
    2022/07/05 09:16:07.157687 cannot process incoming connection: invalid PSK identity
    2022/07/05 09:16:08.018188 [101] cannot send to [zbxserver.domain.com:10051]: 140451689509400:error:140840FF:SSL routines:ssl3_connect:unknown state:s3_clnt.c:646:

    It sometimes works without error (with encryption enabled) and some other it just fails.

    Could it be due to SSL versions?

    Clients SSL version: OpenSSL 1.0.2p-fips 14 Aug 2018
    Zabbix Server SSL version: OpenSSL 1.1.1d 10 Sep 2019
  • LenR
    Senior Member
    • Sep 2009
    • 1005

    #2
    Is the time off on the client? There used to be a limit on how much time delta there could be in an ssl session.

    Comment

    • mcflurry
      Member
      • Jun 2022
      • 32

      #3
      Originally posted by LenR
      Is the time off on the client? There used to be a limit on how much time delta there could be in an ssl session.
      What do you mean?

      It's been 2 days without that issue... maybe it's gone.... will check it out for the coming days.

      Comment

      • muelli
        Member
        • Jun 2021
        • 68

        #4
        if the time is not correct and the difference between time on server and time on agent/client is too high, there can be problems.
        So check time sync first....

        Comment

        Working...