Hi
One of the policy pod is failing because of the expired certificate. How do we
renew the certificate in AAF?. Any documentation on the steps to be followed ?
XXXXX@ip-XXXXXX:~$ kubectl get pods -n onap | grep policy
dev-policy-apex-pdp-0 1/1 Running 0
11h
dev-policy-api-5c4889c84c-crjfc 1/1 Running 0
11h
dev-policy-distribution-6857b6d98-55n2c 1/1 Running 0
11h
dev-policy-drools-pdp-0 1/1 Running 0
11h
dev-policy-galera-config-6zwgp 0/1 Completed 0
11h
dev-policy-mariadb-0 1/1 Running 0
11h
dev-policy-pap-65884676bf-49xhp 1/1 Running 0
11h
dev-policy-xacml-pdp-58b57fc8ff-wsw9r 0/1 CrashLoopBackOff 177
10h
[2021-08-06T16:58:22.028+00:00|ERROR|CambriaSimplerBatchPublisher|pool-2-thread-1]
PUB_CHRONIC_FAILURE: Send failure count is 57, above threshold 10.
[2021-08-06T16:58:23.056+00:00|INFO|XacmlPdpHearbeatPublisher|pool-3-thread-1]
Sending Xacml PDP heartbeat to the PAP -
PdpStatus(super=PdpMessage(messageName=PDP_STATUS,
requestId=5cc50689-4d49-4c74-90eb-11b80247674b, timestampMs=1628269103056,
name=dev-policy-xacml-pdp-58b57fc8ff-wsw9r, pdpGroup=defaultGroup,
pdpSubgroup=null), pdpType=xacml, state=PASSIVE, healthy=HEALTHY,
description=null, policies=[], deploymentInstanceInfo=null, properties=null,
statistics=null, response=null)
[2021-08-06T16:58:23.057+00:00|INFO|network|pool-3-thread-1]
[OUT|DMAAP|POLICY-PDP-PAP]
{"pdpType":"xacml","state":"PASSIVE","healthy":"HEALTHY","policies":[],"messageName":"PDP_STATUS","requestId":"5cc50689-4d49-4c74-90eb-11b80247674b","timestampMs":1628269103056,"name":"dev-policy-xacml-pdp-58b57fc8ff-wsw9r","pdpGroup":"defaultGroup"}
[2021-08-06T16:58:23.070+00:00|INFO|CambriaSimplerBatchPublisher|pool-2-thread-1]
sending 2 msgs to /events/POLICY-PDP-PAP. Oldest: 60014 ms
[2021-08-06T16:58:23.070+00:00|WARN|HostSelector|pool-2-thread-1] All hosts
were blacklisted; reverting to full set of hosts.
[2021-08-06T16:58:23.070+00:00|INFO|HttpClient|pool-2-thread-1] POST
https://message-router:3905/events/POLICY-PDP-PAP (anonymous) ...
[2021-08-06T16:58:23.078+00:00|WARN|HttpClient|pool-2-thread-1] Error executing
HTTP request. PKIX path validation failed:
java.security.cert.CertPathValidatorException: validity check failed;
blacklisting for 2 minutes
[2021-08-06T16:58:23.078+00:00|WARN|CambriaSimplerBatchPublisher|pool-2-thread-1]
PKIX path validation failed: java.security.cert.CertPathValidatorException:
validity check failed
javax.net.ssl.SSLHandshakeException: PKIX path validation failed:
java.security.cert.CertPathValidatorException: validity check failed
at java.base/sun.security.ssl.Alert.createSSLException(Alert.java:131)
at java.base/sun.security.ssl.TransportContext.fatal(TransportContext.java:326)
at java.base/sun.security.ssl.TransportContext.fatal(TransportContext.java:269)
at java.base/sun.security.ssl.TransportContext.fatal(TransportContext.java:264)
at
java.base/sun.security.ssl.CertificateMessage$T12CertificateConsumer.checkServerCerts(CertificateMessage.java:645)
at
java.base/sun.security.ssl.CertificateMessage$T12CertificateConsumer.onCertificate(CertificateMessage.java:464)
Regards,
Praveen
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#23468): https://lists.onap.org/g/onap-discuss/message/23468
Mute This Topic: https://lists.onap.org/mt/84764257/21656
Mute #policy:https://lists.onap.org/g/onap-discuss/mutehashtag/policy
Mute #aaf:https://lists.onap.org/g/onap-discuss/mutehashtag/aaf
Mute #policy
dev-policy-xacml-pdp:https://lists.onap.org/g/onap-discuss/mutehashtag/policy
dev-policy-xacml-pdp
Group Owner: [email protected]
Unsubscribe: https://lists.onap.org/g/onap-discuss/unsub
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-