Hitachi

JP1 Version 12 JP1/Integrated Management 2 - Manager Messages


KAVB1994-E

The SSL communication processing failed. (cause: reason, connection-destination host name: connection-destination-host-name)

The request from the client is ignored due to a failure in SSL communication processing.

S:

Terminates event search processing.

O:

If the cause is The CN or SAN of the server certificate does not match with the host name of the connection destination:

  • Verify that the CN or SAN in the server certificate of the host at the connection destination matches the host name specified as the destination for event search.

If the cause is SSL handshake failed:

  • Check the network environment.

  • If the manager does not use the communication encryption function, the communication encryption function on the search must be disabled. If the communication encryption function is enabled, add the manager host name in the non-SSL communication host configuration file of the search host.

  • If the manager uses the communication encryption function and the function is disabled on the search host, check that the search host name is registered in the non-SSL communication host configuration file of the manager. If not, register the name.

  • If both the manager and the search host use the communication encryption function, check that the host names of both are not registered in the non-SSL communication host configuration files of them. If the names are found, remove both the host names.

  • Check that a root certificate as a counterpart of the server certificate for the connected host is found in the manager. If not, put it in place.

If there is no problem with the above settings, check the following on the search host:

  • Check if the communication encryption function is enabled on the connected host. If it is enabled, check that the non-SSL communication host configuration file does not contain the host name of the connection destination.

If the cause is There is no common SSL version or common encryption suite:

  • Specify the common SSL version or common encryption suite.

If the cause is The server certificate of the connection destination has expired:

  • Check if the server certificate of the connected host is not expired.

  • If it is expired, update the server certificate.