Re: [Spacewalk-list] Registration to the new server via rhnreg_ks returns an SSL error

2019-03-01 Thread Zhou, Rui A. (NSB - CN/Shanghai)
My problem was resloved, I reset my login password and it work  now!

-Original Message-
From: Zhou, Rui A. (NSB - CN/Shanghai) 
Sent: 2019年3月1日 19:02
To: spacewalk-list@redhat.com; robert.pasche...@web.de
Cc: Zhu, Ting (NSB - CN/Shanghai) 
Subject: RE: [Spacewalk-list] Registration to the new server via rhnreg_ks 
returns an SSL error

Very sad to say, they are the same, I think if the file in hosts has some 
impacts? I find I have not write the configuration before. I will try and tell 
the result later.
[root@spacewalk-server pxelinux.cfg]# cat /etc/hosts
127.0.0.1   localhost localhost.localdomain localhost4 localhost4.localdomain4
::1 localhost localhost.localdomain localhost6 localhost6.localdomain6
135.251.206.139 spacewalk-server

Client:
[root@FNSHA172 yum.repos.d]# cat /usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
91:88:95:56:dd:6c:6d:0d

Server:
[root@spacewalk-server ~]# cat /var/www/html/pub/RHN-ORG-TRUSTED-SSL-CERT
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
91:88:95:56:dd:6c:6d:0d

-Original Message-
From: spacewalk-list-boun...@redhat.com 
[mailto:spacewalk-list-boun...@redhat.com] On Behalf Of p.cook...@bham.ac.uk
Sent: 2019年3月1日 17:09
To: robert.pasche...@web.de; spacewalk-list@redhat.com
Subject: Re: [Spacewalk-list] Registration to the new server via rhnreg_ks 
returns an SSL error

Whether you re-installed the Spacewalk application on the same server or a 
different one, a new certificate should have been produced after running 
"spacewalk-setup."

Subsequently, the certificate can be viewed on the server:

cat /var/www/html/pub/RHN-ORG-TRUSTED-SSL-CERT

OR

WebUI -> Systems (Top Menu) -> Kickstart (Left Menu) -> GPG and SSL Keys -> 
RHN-ORG-TRUSTED-SSL-CERT -> Key contents

If everything has been done correctly, to register the client, the certificate 
can be viewed on there too:

cat /usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT

If they don't match, you'll have a problem!

Like Robert says, it seems to be "just" a SSL issue really but, obviously, the 
certificate is being generated by the Spacewalk application installation.

Regards
Phil

-Original Message-
From: robert.pasche...@web.de 
Sent: 28 February 2019 16:47
To: spacewalk-list@redhat.com; Philip Cookson (IT Services) 
; spacewalk-list@redhat.com
Subject: Re: [Spacewalk-list] Registration to the new server via rhnreg_ks 
returns an SSL error

Am 28. Februar 2019 11:10:57 MEZ schrieb "p.cook...@bham.ac.uk" 
:
>Obviously, that will work but you won’t be using the secure layer or 
>addressing the underlying problem!
>
>If you’re getting the same problem with a new client system I can see 
>how you may think it’s a server related issue. However, the Spacewalk 
>certificate is generated during installation so it would be un-usual, I 
>would have thought?
>
>Did you add the certificate to the database (certutil -d 
>sql:/etc/pki/nssdb -An RHN-ORG-TRUSTED-SSL-CERT -t C,, -ai 
>/usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT), too, as you only mention 
>getting the rpm (rpm -Uvh 
>http://spacewalk-server/pub/rhn-org-trusted-ssl-cert-1.0-1.noarch.rpm)?
>
>Regards
>Phil
>
>From: spacewalk-list-boun...@redhat.com 
> On Behalf Of 
>rui.a.z...@nokia-sbell.com
>Sent: 28 February 2019 09:51
>To: spacewalk-list@redhat.com
>Cc: Zhu, Ting (NSB - CN/Shanghai) 
>Subject: Re: [Spacewalk-list] Registration to the new server via 
>rhnreg_ks returns an SSL error
>
>
>I think this may not the problem of the client, when I try to add new 
>client server it also has the error: The SSL certificate failed 
>verification.
>I find this help, change the
>--serverUrl=https://spacewalk-server/XMLRPC to 
>--serverUrl=http://spacewalk-server/XMLRPC.  The system can be 
>registerd,  The reason maybe:
>
>*   System did not have the correct SSL certificate.(I check, server
>and client have the same sslCACert)
>  *   SSL certificate was corrupted.(how to explain this?)

This is just a standard SSL issue. Nothing special with spacewalk.

If you're connecting to https://spacewalk-server/, "spacewalk-server" has to be 
included within the SSL certificate. And if that is missing, the certificate 
may be valid but you still get the verification error .

Robert

>
>
>From:
>spacewalk-list-boun...@redhat.comcom> [mailto:spacewalk-list-boun...@redhat.com] On Behalf Of
>p.cook...@bham.ac.uk
>Sent: 2019年2月28日 17:35
>To: spacewalk-list@redhat.com
>Subject: Re: [Spacewalk-list] Registration to the new server via 
>rhnreg_ks returns an SSL error
>
>Hi
>
>It’s a little more involved than that! I produced these notes, for 
>myself, when un-registering a system from a Dev Spacewalk Server and 
>registering it with a Test Spacewalk Server. It’s effectively the same 
>thing that you need to do though.
>
>
>Spacewalk does not provide an option to 

Re: [Spacewalk-list] Spacewalk mail not being sent

2019-03-01 Thread Laszlo Danielisz
Ihor, just FYI, your Delta Dental's signature, phone, email all is in your
email.
I'm not sure if you should share these information.

On Fri, Mar 1, 2019 at 10:38 AM Ihor Lawrin 
wrote:

> Mail generated by our Spacewalk server (2.9) is not being sent out.
>
> Example: when a new Spacewalk user is created, an email is sent out to the
> user. This fails. See below error in /var/log/maillog
>
>
>
> Mail sent via command line works fine.
>
>
>
> Feb 28 15:08:12 cmoswitomcv0001 postfix/smtpd[29685]: connect from
> localhost[127.0.0.1]
>
> Feb 28 15:08:12 cmoswitomcv0001 postfix/smtpd[29685]: NOQUEUE: reject:
> RCPT from localhost[127.0.0.1]: 554 5.7.1 :
> Recipient address rejected: Access denied; from=<
> dev-n...@cmoswitomcv0001.ddmi.intra.renhsc.com> to=<
> user...@deltadentalmi.com> proto=ESMTP helo=<
> cmoswitomcv0001.ddmi.intra.renhsc.com>
>
> Feb 28 15:08:12 cmoswitomcv0001 postfix/smtpd[29685]: disconnect from
> localhost[127.0.0.1]
>
>
>
>
> *Ihor Lawrin *Technical Services
>
> Senior System Administrator (UNIX)
> Delta Dental of Michigan, Ohio, and Indiana
> (517) 381-4207 Direct Line
> (517) 648-7312 Cell
>
>
>
> [image: cid:2BF1C32F-CF05-469B-B08B-26DA6BF62BA0]
>
> *ISO 9001 Quality Certified  •  Certified Call Center of Excellence  •
> Rated A (Excellent) by A.M. Best Company*
>
>
>
>
> --
> CONFIDENTIALITY NOTICE: The information contained in this email is
> intended only for the person or entity to which it is addressed and may
> contain confidential and/or privileged material. If you are not the
> intended recipient, you are hereby notified that any unauthorized review,
> use, dissemination, distribution or copying of this communication is
> prohibited and may be subject to legal restriction or sanction. If you have
> received this email in error, please notify the sender immediately to
> arrange for return or destruction of the information and all copies. If you
> are the intended recipient but do not wish to receive communications
> through this medium, please advise the sender immediately. Thank you.
> ___
> Spacewalk-list mailing list
> Spacewalk-list@redhat.com
> https://www.redhat.com/mailman/listinfo/spacewalk-list
___
Spacewalk-list mailing list
Spacewalk-list@redhat.com
https://www.redhat.com/mailman/listinfo/spacewalk-list

[Spacewalk-list] Spacewalk mail not being sent

2019-03-01 Thread Ihor Lawrin
Mail generated by our Spacewalk server (2.9) is not being sent out.
Example: when a new Spacewalk user is created, an email is sent out to the 
user. This fails. See below error in /var/log/maillog

Mail sent via command line works fine.

Feb 28 15:08:12 cmoswitomcv0001 postfix/smtpd[29685]: connect from 
localhost[127.0.0.1]
Feb 28 15:08:12 cmoswitomcv0001 postfix/smtpd[29685]: NOQUEUE: reject: RCPT 
from localhost[127.0.0.1]: 554 5.7.1 : Recipient 
address rejected: Access denied; 
from= 
to= proto=ESMTP 
helo=
Feb 28 15:08:12 cmoswitomcv0001 postfix/smtpd[29685]: disconnect from 
localhost[127.0.0.1]

Ihor Lawrin
Technical Services
Senior System Administrator (UNIX)
Delta Dental of Michigan, Ohio, and Indiana
(517) 381-4207 Direct Line
(517) 648-7312 Cell

[cid:2BF1C32F-CF05-469B-B08B-26DA6BF62BA0]
ISO 9001 Quality Certified  *  Certified Call Center of Excellence  *  Rated A 
(Excellent) by A.M. Best Company


**
CONFIDENTIALITY NOTICE: The information contained in this email is intended 
only for the person or entity to which it is addressed and may contain 
confidential and/or privileged material. If you are not the intended recipient, 
you are hereby notified that any unauthorized review, use, dissemination, 
distribution or copying of this communication is prohibited and may be subject 
to legal restriction or sanction. If you have received this email in error, 
please notify the sender immediately to arrange for return or destruction of 
the information and all copies. If you are the intended recipient but do not 
wish to receive communications through this medium, please advise the sender 
immediately. Thank you.
___
Spacewalk-list mailing list
Spacewalk-list@redhat.com
https://www.redhat.com/mailman/listinfo/spacewalk-list

Re: [Spacewalk-list] Spacewalk Mail Configuration

2019-03-01 Thread Elsever Sadigov

Thank you, it works!

I didn't know that postfix using relayhost as gateway. Strange, but 
anyway, it works.


--
Best Regards,

Elsever Sadigov

2/26/2019 13:14, Michael Mraka пишет:

Elsever Sadigov:

Hi, thanks for answers

So if I configure postfix, this will be enough?

Yes, it will.


Or anything else what I need to write to spacewalk configuration file?

--
Best Regards,

Elsever Sadigov

Regards,

--
Michael Mráka
System Management Engineering, Red Hat

___
Spacewalk-list mailing list
Spacewalk-list@redhat.com
https://www.redhat.com/mailman/listinfo/spacewalk-list



___
Spacewalk-list mailing list
Spacewalk-list@redhat.com
https://www.redhat.com/mailman/listinfo/spacewalk-list

Re: [Spacewalk-list] Registration to the new server via rhnreg_ks returns an SSL error

2019-03-01 Thread p.cook...@bham.ac.uk
You're only showing the top of the files there. Is the rest of the information 
the same too, particularly the server name and actual key? All the responses 
from "spacewalk-setup" should be in there really.

Regards
Phil

-Original Message-
From: spacewalk-list-boun...@redhat.com  On 
Behalf Of rui.a.z...@nokia-sbell.com
Sent: 01 March 2019 11:02
To: spacewalk-list@redhat.com; robert.pasche...@web.de
Cc: Zhu, Ting (NSB - CN/Shanghai) 
Subject: Re: [Spacewalk-list] Registration to the new server via rhnreg_ks 
returns an SSL error

Very sad to say, they are the same, I think if the file in hosts has some 
impacts? I find I have not write the configuration before. I will try and tell 
the result later.
[root@spacewalk-server pxelinux.cfg]# cat /etc/hosts
127.0.0.1   localhost localhost.localdomain localhost4 localhost4.localdomain4
::1 localhost localhost.localdomain localhost6 localhost6.localdomain6
135.251.206.139 spacewalk-server

Client:
[root@FNSHA172 yum.repos.d]# cat /usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
91:88:95:56:dd:6c:6d:0d

Server:
[root@spacewalk-server ~]# cat /var/www/html/pub/RHN-ORG-TRUSTED-SSL-CERT
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
91:88:95:56:dd:6c:6d:0d

-Original Message-
From: spacewalk-list-boun...@redhat.com 
[mailto:spacewalk-list-boun...@redhat.com] On Behalf Of p.cook...@bham.ac.uk
Sent: 2019年3月1日 17:09
To: robert.pasche...@web.de; spacewalk-list@redhat.com
Subject: Re: [Spacewalk-list] Registration to the new server via rhnreg_ks 
returns an SSL error

Whether you re-installed the Spacewalk application on the same server or a 
different one, a new certificate should have been produced after running 
"spacewalk-setup."

Subsequently, the certificate can be viewed on the server:

cat /var/www/html/pub/RHN-ORG-TRUSTED-SSL-CERT

OR

WebUI -> Systems (Top Menu) -> Kickstart (Left Menu) -> GPG and SSL Keys -> 
RHN-ORG-TRUSTED-SSL-CERT -> Key contents

If everything has been done correctly, to register the client, the certificate 
can be viewed on there too:

cat /usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT

If they don't match, you'll have a problem!

Like Robert says, it seems to be "just" a SSL issue really but, obviously, the 
certificate is being generated by the Spacewalk application installation.

Regards
Phil

-Original Message-
From: robert.pasche...@web.de 
Sent: 28 February 2019 16:47
To: spacewalk-list@redhat.com; Philip Cookson (IT Services) 
; spacewalk-list@redhat.com
Subject: Re: [Spacewalk-list] Registration to the new server via rhnreg_ks 
returns an SSL error

Am 28. Februar 2019 11:10:57 MEZ schrieb "p.cook...@bham.ac.uk" 
:
>Obviously, that will work but you won’t be using the secure layer or 
>addressing the underlying problem!
>
>If you’re getting the same problem with a new client system I can see 
>how you may think it’s a server related issue. However, the Spacewalk 
>certificate is generated during installation so it would be un-usual, I 
>would have thought?
>
>Did you add the certificate to the database (certutil -d 
>sql:/etc/pki/nssdb -An RHN-ORG-TRUSTED-SSL-CERT -t C,, -ai 
>/usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT), too, as you only mention 
>getting the rpm (rpm -Uvh 
>http://spacewalk-server/pub/rhn-org-trusted-ssl-cert-1.0-1.noarch.rpm)?
>
>Regards
>Phil
>
>From: spacewalk-list-boun...@redhat.com 
> On Behalf Of 
>rui.a.z...@nokia-sbell.com
>Sent: 28 February 2019 09:51
>To: spacewalk-list@redhat.com
>Cc: Zhu, Ting (NSB - CN/Shanghai) 
>Subject: Re: [Spacewalk-list] Registration to the new server via 
>rhnreg_ks returns an SSL error
>
>
>I think this may not the problem of the client, when I try to add new 
>client server it also has the error: The SSL certificate failed 
>verification.
>I find this help, change the
>--serverUrl=https://spacewalk-server/XMLRPC to 
>--serverUrl=http://spacewalk-server/XMLRPC.  The system can be 
>registerd,  The reason maybe:
>
>*   System did not have the correct SSL certificate.(I check, server
>and client have the same sslCACert)
>  *   SSL certificate was corrupted.(how to explain this?)

This is just a standard SSL issue. Nothing special with spacewalk.

If you're connecting to https://spacewalk-server/, "spacewalk-server" has to be 
included within the SSL certificate. And if that is missing, the certificate 
may be valid but you still get the verification error .

Robert

>
>
>From:
>spacewalk-list-boun...@redhat.comcom> [mailto:spacewalk-list-boun...@redhat.com] On Behalf Of
>p.cook...@bham.ac.uk
>Sent: 2019年2月28日 17:35
>To: spacewalk-list@redhat.com
>Subject: Re: [Spacewalk-list] Registration to the new server via 
>rhnreg_ks returns an SSL error
>
>Hi
>
>It’s a little more involved than that! I produced these notes, for 
>myself, when un-registering 

Re: [Spacewalk-list] Registration to the new server via rhnreg_ks returns an SSL error

2019-03-01 Thread Zhou, Rui A. (NSB - CN/Shanghai)
Very sad to say, they are the same, I think if the file in hosts has some 
impacts? I find I have not write the configuration before. I will try and tell 
the result later.
[root@spacewalk-server pxelinux.cfg]# cat /etc/hosts
127.0.0.1   localhost localhost.localdomain localhost4 localhost4.localdomain4
::1 localhost localhost.localdomain localhost6 localhost6.localdomain6
135.251.206.139 spacewalk-server

Client:
[root@FNSHA172 yum.repos.d]# cat /usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
91:88:95:56:dd:6c:6d:0d

Server:
[root@spacewalk-server ~]# cat /var/www/html/pub/RHN-ORG-TRUSTED-SSL-CERT
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
91:88:95:56:dd:6c:6d:0d

-Original Message-
From: spacewalk-list-boun...@redhat.com 
[mailto:spacewalk-list-boun...@redhat.com] On Behalf Of p.cook...@bham.ac.uk
Sent: 2019年3月1日 17:09
To: robert.pasche...@web.de; spacewalk-list@redhat.com
Subject: Re: [Spacewalk-list] Registration to the new server via rhnreg_ks 
returns an SSL error

Whether you re-installed the Spacewalk application on the same server or a 
different one, a new certificate should have been produced after running 
"spacewalk-setup."

Subsequently, the certificate can be viewed on the server:

cat /var/www/html/pub/RHN-ORG-TRUSTED-SSL-CERT

OR

WebUI -> Systems (Top Menu) -> Kickstart (Left Menu) -> GPG and SSL Keys -> 
RHN-ORG-TRUSTED-SSL-CERT -> Key contents

If everything has been done correctly, to register the client, the certificate 
can be viewed on there too:

cat /usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT

If they don't match, you'll have a problem!

Like Robert says, it seems to be "just" a SSL issue really but, obviously, the 
certificate is being generated by the Spacewalk application installation.

Regards
Phil

-Original Message-
From: robert.pasche...@web.de 
Sent: 28 February 2019 16:47
To: spacewalk-list@redhat.com; Philip Cookson (IT Services) 
; spacewalk-list@redhat.com
Subject: Re: [Spacewalk-list] Registration to the new server via rhnreg_ks 
returns an SSL error

Am 28. Februar 2019 11:10:57 MEZ schrieb "p.cook...@bham.ac.uk" 
:
>Obviously, that will work but you won’t be using the secure layer or 
>addressing the underlying problem!
>
>If you’re getting the same problem with a new client system I can see 
>how you may think it’s a server related issue. However, the Spacewalk 
>certificate is generated during installation so it would be un-usual, I 
>would have thought?
>
>Did you add the certificate to the database (certutil -d 
>sql:/etc/pki/nssdb -An RHN-ORG-TRUSTED-SSL-CERT -t C,, -ai 
>/usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT), too, as you only mention 
>getting the rpm (rpm -Uvh 
>http://spacewalk-server/pub/rhn-org-trusted-ssl-cert-1.0-1.noarch.rpm)?
>
>Regards
>Phil
>
>From: spacewalk-list-boun...@redhat.com 
> On Behalf Of 
>rui.a.z...@nokia-sbell.com
>Sent: 28 February 2019 09:51
>To: spacewalk-list@redhat.com
>Cc: Zhu, Ting (NSB - CN/Shanghai) 
>Subject: Re: [Spacewalk-list] Registration to the new server via 
>rhnreg_ks returns an SSL error
>
>
>I think this may not the problem of the client, when I try to add new 
>client server it also has the error: The SSL certificate failed 
>verification.
>I find this help, change the
>--serverUrl=https://spacewalk-server/XMLRPC to 
>--serverUrl=http://spacewalk-server/XMLRPC.  The system can be 
>registerd,  The reason maybe:
>
>*   System did not have the correct SSL certificate.(I check, server
>and client have the same sslCACert)
>  *   SSL certificate was corrupted.(how to explain this?)

This is just a standard SSL issue. Nothing special with spacewalk.

If you're connecting to https://spacewalk-server/, "spacewalk-server" has to be 
included within the SSL certificate. And if that is missing, the certificate 
may be valid but you still get the verification error .

Robert

>
>
>From:
>spacewalk-list-boun...@redhat.comcom> [mailto:spacewalk-list-boun...@redhat.com] On Behalf Of
>p.cook...@bham.ac.uk
>Sent: 2019年2月28日 17:35
>To: spacewalk-list@redhat.com
>Subject: Re: [Spacewalk-list] Registration to the new server via 
>rhnreg_ks returns an SSL error
>
>Hi
>
>It’s a little more involved than that! I produced these notes, for 
>myself, when un-registering a system from a Dev Spacewalk Server and 
>registering it with a Test Spacewalk Server. It’s effectively the same 
>thing that you need to do though.
>
>
>Spacewalk does not provide an option to un-register a client system 
>(similar to registering - “rhnreg_ks”) - the only option is to remove 
>the client system’s profile from the Spacewalk server.
>
>To remove a client’s profile from the Spacewalk server perform these
>steps:
>
>
>  1.  Log in to the Spacewalk Console.
>2.  Click on the Systems tab in the top navigation bar and then 

Re: [Spacewalk-list] Registration to the new server via rhnreg_ks returns an SSL error

2019-03-01 Thread p.cook...@bham.ac.uk
Whether you re-installed the Spacewalk application on the same server or a 
different one, a new certificate should have been produced after running 
"spacewalk-setup."

Subsequently, the certificate can be viewed on the server:

cat /var/www/html/pub/RHN-ORG-TRUSTED-SSL-CERT

OR

WebUI -> Systems (Top Menu) -> Kickstart (Left Menu) -> GPG and SSL Keys -> 
RHN-ORG-TRUSTED-SSL-CERT -> Key contents

If everything has been done correctly, to register the client, the certificate 
can be viewed on there too:

cat /usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT

If they don't match, you'll have a problem!

Like Robert says, it seems to be "just" a SSL issue really but, obviously, the 
certificate is being generated by the Spacewalk application installation.

Regards
Phil

-Original Message-
From: robert.pasche...@web.de  
Sent: 28 February 2019 16:47
To: spacewalk-list@redhat.com; Philip Cookson (IT Services) 
; spacewalk-list@redhat.com
Subject: Re: [Spacewalk-list] Registration to the new server via rhnreg_ks 
returns an SSL error

Am 28. Februar 2019 11:10:57 MEZ schrieb "p.cook...@bham.ac.uk" 
:
>Obviously, that will work but you won’t be using the secure layer or 
>addressing the underlying problem!
>
>If you’re getting the same problem with a new client system I can see 
>how you may think it’s a server related issue. However, the Spacewalk 
>certificate is generated during installation so it would be un-usual, I 
>would have thought?
>
>Did you add the certificate to the database (certutil -d 
>sql:/etc/pki/nssdb -An RHN-ORG-TRUSTED-SSL-CERT -t C,, -ai 
>/usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT), too, as you only mention 
>getting the rpm (rpm -Uvh 
>http://spacewalk-server/pub/rhn-org-trusted-ssl-cert-1.0-1.noarch.rpm)?
>
>Regards
>Phil
>
>From: spacewalk-list-boun...@redhat.com 
> On Behalf Of 
>rui.a.z...@nokia-sbell.com
>Sent: 28 February 2019 09:51
>To: spacewalk-list@redhat.com
>Cc: Zhu, Ting (NSB - CN/Shanghai) 
>Subject: Re: [Spacewalk-list] Registration to the new server via 
>rhnreg_ks returns an SSL error
>
>
>I think this may not the problem of the client, when I try to add new 
>client server it also has the error: The SSL certificate failed 
>verification.
>I find this help, change the
>--serverUrl=https://spacewalk-server/XMLRPC to 
>--serverUrl=http://spacewalk-server/XMLRPC.  The system can be 
>registerd,  The reason maybe:
>
>*   System did not have the correct SSL certificate.(I check, server
>and client have the same sslCACert)
>  *   SSL certificate was corrupted.(how to explain this?)

This is just a standard SSL issue. Nothing special with spacewalk.

If you're connecting to https://spacewalk-server/, "spacewalk-server" has to be 
included within the SSL certificate. And if that is missing, the certificate 
may be valid but you still get the verification error .

Robert

>
>
>From:
>spacewalk-list-boun...@redhat.comcom> [mailto:spacewalk-list-boun...@redhat.com] On Behalf Of 
>p.cook...@bham.ac.uk
>Sent: 2019年2月28日 17:35
>To: spacewalk-list@redhat.com
>Subject: Re: [Spacewalk-list] Registration to the new server via 
>rhnreg_ks returns an SSL error
>
>Hi
>
>It’s a little more involved than that! I produced these notes, for 
>myself, when un-registering a system from a Dev Spacewalk Server and 
>registering it with a Test Spacewalk Server. It’s effectively the same 
>thing that you need to do though.
>
>
>Spacewalk does not provide an option to un-register a client system 
>(similar to registering - “rhnreg_ks”) - the only option is to remove 
>the client system’s profile from the Spacewalk server.
>
>To remove a client’s profile from the Spacewalk server perform these
>steps:
>
>
>  1.  Log in to the Spacewalk Console.
>2.  Click on the Systems tab in the top navigation bar and then click 
>on the name of the system which you want to remove from the Systems 
>List.
>  3.  Click the Delete System link in the top-right corner of the page.
>4.  Confirm system profile deletion by clicking the Delete Profile 
>button.
>5.  Now go to the client system and execute below command to remove the 
>associated System ID file:
>
># rm /etc/sysconfig/rhn/systemid
>
>In addition, remove Spacewalk certificate for Development and add 
>certificate for Test. Then register client system with Test Spacewalk
>server:
>
># certutil -d sql:/etc/pki/nssdb -Dn RHN-ORG-TRUSTED-SSL-CERT -t C,, 
>-ai /usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT
># rpm -ev rhn-org-trusted-ssl-cert-1.0-1.noarch
># rpm -Uvh https://https://%3cTest>
>Server>/pub/rhn-org-trusted-ssl-cert-1.0-1.noarch.rpm
># certutil -d sql:/etc/pki/nssdb -An RHN-ORG-TRUSTED-SSL-CERT -t C,, 
>-ai /usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT
># rhnreg_ks --serverUrl=https:///XMLRPC 
>--sslCACert=/usr/share/rhn/RHN-ORG-TRUSTED-SSL-CERT
>--activationkey=[ACTIVATION KEY]
>
>
>Note, if you’re using OSAD, the service may have stopped during this