Ad Widget

Collapse

Encryption and invalid PSK

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • is95kiko
    Junior Member
    • Feb 2016
    • 2

    #1

    Encryption and invalid PSK

    I've installed server 3.0.0-1 and agent 3.0.0-1 in to Centos 7 from zabbix.com rpm's.
    When I try to configure agent, I cannot get it started because of the "invalid PSK in file" error.

    My agent config is:
    TLSConnect=psk
    TLSAccept=psk
    TLSPSKIdentity=jees
    TLSPSKFile=/etc/pki/tls/private/kekkonen.psk

    and the PSK file:

    # ls -la /etc/pki/tls/private/kekkonen.psk
    -rw------- 1 zabbix zabbix 74 Feb 24 14:09 /etc/pki/tls/private/kekkonen.psk

    which contains:
    jees:ffba15a9f2f3b6856879ae5b1bdfda1ea4ee202f48111 d40b0c57748a6c2afcbaaaa

    and it was created by:
    # psktool -u jees -p kekkonen.psk -s 32
    Generating a random key for user 'jees'
    Key stored to kekkonen.psk

    When I try to start agent, it won't start (from zabbix_agentd.log):

    3533:20160225:075307.432 invalid PSK in file "/etc/pki/tls/private/kekkonen.psk"
    3536:20160225:075307.433 invalid PSK in file "/etc/pki/tls/private/kekkonen.psk"
    3534:20160225:075307.433 agent #3 started[listener #2]
    3531:20160225:075307.434 One child process died (PID:3533,exitcode/signal:1). Exiting ...
    3534:20160225:075307.435 invalid PSK in file "/etc/pki/tls/private/kekkonen.psk"
    zabbix_agentd [3531]: Error waiting for process with PID 3533: [10] No child processes
    3531:20160225:075307.437 Zabbix Agent stopped. Zabbix 3.0.0 (revision 58460).


    Anyone else having this problem or any ideas what's wrong?
  • glebs.ivanovskis
    Senior Member
    • Jul 2015
    • 237

    #2
    You need to delete PSK identity from PSK file, Zabbix expects there only PSK itself.

    Comment

    • is95kiko
      Junior Member
      • Feb 2016
      • 2

      #3
      Originally posted by glebs.ivanovskis
      You need to delete PSK identity from PSK file, Zabbix expects there only PSK itself.
      https://www.zabbix.com/documentation...generating_psk
      Yep, this was RTFM, thanks.

      Comment

      Working...