Hi

One of the policy pod is failing because of the expired certificate. How do we 
renew the certificate in AAF?. Any documentation on the steps to be followed ?

XXXXX@ip-XXXXXX:~$ kubectl get pods -n onap | grep policy

dev-policy-apex-pdp-0                           1/1     Running            0    
      11h

dev-policy-api-5c4889c84c-crjfc                 1/1     Running            0    
      11h

dev-policy-distribution-6857b6d98-55n2c         1/1     Running            0    
      11h

dev-policy-drools-pdp-0                         1/1     Running            0    
      11h

dev-policy-galera-config-6zwgp                  0/1     Completed          0    
      11h

dev-policy-mariadb-0                            1/1     Running            0    
      11h

dev-policy-pap-65884676bf-49xhp                 1/1     Running            0    
      11h

dev-policy-xacml-pdp-58b57fc8ff-wsw9r           0/1     CrashLoopBackOff   177  
      10h

[2021-08-06T16:58:22.028+00:00|ERROR|CambriaSimplerBatchPublisher|pool-2-thread-1]
 PUB_CHRONIC_FAILURE: Send failure count is 57, above threshold 10.

[2021-08-06T16:58:23.056+00:00|INFO|XacmlPdpHearbeatPublisher|pool-3-thread-1] 
Sending Xacml PDP heartbeat to the PAP - 
PdpStatus(super=PdpMessage(messageName=PDP_STATUS, 
requestId=5cc50689-4d49-4c74-90eb-11b80247674b, timestampMs=1628269103056, 
name=dev-policy-xacml-pdp-58b57fc8ff-wsw9r, pdpGroup=defaultGroup, 
pdpSubgroup=null), pdpType=xacml, state=PASSIVE, healthy=HEALTHY, 
description=null, policies=[], deploymentInstanceInfo=null, properties=null, 
statistics=null, response=null)

[2021-08-06T16:58:23.057+00:00|INFO|network|pool-3-thread-1] 
[OUT|DMAAP|POLICY-PDP-PAP]

{"pdpType":"xacml","state":"PASSIVE","healthy":"HEALTHY","policies":[],"messageName":"PDP_STATUS","requestId":"5cc50689-4d49-4c74-90eb-11b80247674b","timestampMs":1628269103056,"name":"dev-policy-xacml-pdp-58b57fc8ff-wsw9r","pdpGroup":"defaultGroup"}

[2021-08-06T16:58:23.070+00:00|INFO|CambriaSimplerBatchPublisher|pool-2-thread-1]
 sending 2 msgs to /events/POLICY-PDP-PAP. Oldest: 60014 ms

[2021-08-06T16:58:23.070+00:00|WARN|HostSelector|pool-2-thread-1] All hosts 
were blacklisted; reverting to full set of hosts.

[2021-08-06T16:58:23.070+00:00|INFO|HttpClient|pool-2-thread-1] POST 
https://message-router:3905/events/POLICY-PDP-PAP (anonymous) ...

[2021-08-06T16:58:23.078+00:00|WARN|HttpClient|pool-2-thread-1] Error executing 
HTTP request. PKIX path validation failed: 
java.security.cert.CertPathValidatorException: validity check failed; 
blacklisting for 2 minutes

[2021-08-06T16:58:23.078+00:00|WARN|CambriaSimplerBatchPublisher|pool-2-thread-1]
 PKIX path validation failed: java.security.cert.CertPathValidatorException: 
validity check failed

javax.net.ssl.SSLHandshakeException: PKIX path validation failed: 
java.security.cert.CertPathValidatorException: validity check failed

at java.base/sun.security.ssl.Alert.createSSLException(Alert.java:131)

at java.base/sun.security.ssl.TransportContext.fatal(TransportContext.java:326)

at java.base/sun.security.ssl.TransportContext.fatal(TransportContext.java:269)

at java.base/sun.security.ssl.TransportContext.fatal(TransportContext.java:264)

at 
java.base/sun.security.ssl.CertificateMessage$T12CertificateConsumer.checkServerCerts(CertificateMessage.java:645)

at 
java.base/sun.security.ssl.CertificateMessage$T12CertificateConsumer.onCertificate(CertificateMessage.java:464)

Regards,

Praveen


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#23468): https://lists.onap.org/g/onap-discuss/message/23468
Mute This Topic: https://lists.onap.org/mt/84764257/21656
Mute #policy:https://lists.onap.org/g/onap-discuss/mutehashtag/policy
Mute #aaf:https://lists.onap.org/g/onap-discuss/mutehashtag/aaf
Mute #policy 
dev-policy-xacml-pdp:https://lists.onap.org/g/onap-discuss/mutehashtag/policy 
dev-policy-xacml-pdp
Group Owner: [email protected]
Unsubscribe: https://lists.onap.org/g/onap-discuss/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-


Reply via email to