ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Port from SW - Salt master rsa key issue

    IT Discussion
    salt salt master salt minion rsa
    6
    60
    9.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dgingerich @scottalanmiller
      last edited by

      @scottalanmiller I have tried repeatedly to delete all keys and rejoin the minions. It doesn't work. The keys are seen and accepted, but then the minions refuse to authenticate. I have even deleted all keys, uninstalled salt from the minions, deleted all cached data, reinstalled salt minion, and resubmitted keys, and still, trying a ping to all minions right after accpeting the keys results in no connections. running salt-minion -l debug shows that the minions think the masters' keys don't authenticate. It is very frustrating.

      scottalanmillerS 1 Reply Last reply Reply Quote 2
      • scottalanmillerS
        scottalanmiller @dgingerich
        last edited by

        @dgingerich said in Port from SW - Salt master rsa key issue:

        @scottalanmiller I have tried repeatedly to delete all keys and rejoin the minions. It doesn't work. The keys are seen and accepted, but then the minions refuse to authenticate. I have even deleted all keys, uninstalled salt from the minions, deleted all cached data, reinstalled salt minion, and resubmitted keys, and still, trying a ping to all minions right after accpeting the keys results in no connections. running salt-minion -l debug shows that the minions think the masters' keys don't authenticate. It is very frustrating.

        That's really weird. Do you have a new minion that has never joined to test? The question is... is something lingering on that we don't realize OR is there something broken no the master, like it is handing out one public key but using a different private once it receives the data.

        D 1 Reply Last reply Reply Quote 0
        • DustinB3403D
          DustinB3403
          last edited by

          This post is deleted!
          1 Reply Last reply Reply Quote 0
          • DustinB3403D
            DustinB3403
            last edited by DustinB3403

            I'm no salt expert (I've only played with it a few times) but just wanted to ask and confirm something about your RSA keys.

            Are you entering a password when you generate the pairs or no?

            D 1 Reply Last reply Reply Quote 0
            • D
              dgingerich @scottalanmiller
              last edited by

              @scottalanmiller Yes, (a point where we think alike) I just spun up another ubuntu system for a minion to test the master. Same result. The minion submits the key, I accept the key on the master and immediately try test.ping, and nothing. salt-minion -l debug shows the exact same error about authentication. It has to be something on the masters. However, I don't want to have to rebuild the masters because the rsa keys I generated will have to be replaced on the git repository, resulting in a lost day.

              Management is expecting this to be up by Monday, but they just finalized the service structure yesterday. I think they expect me to work over the weekend.

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller
                last edited by

                How is the GIT taking that long? What are you using for GIT? I use a normal user account for GIT on my masters and I can set it up in seconds.

                D 1 Reply Last reply Reply Quote 0
                • D
                  dgingerich @scottalanmiller
                  last edited by

                  @scottalanmiller It's a matter of the person putting the keys into the repository config.

                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @dgingerich
                    last edited by

                    @dgingerich said in Port from SW - Salt master rsa key issue:

                    @scottalanmiller It's a matter of the person putting the keys into the repository config.

                    We use GitLab, it's basically instant.

                    D 1 Reply Last reply Reply Quote 0
                    • D
                      dgingerich @DustinB3403
                      last edited by

                      @DustinB3403

                      @DustinB3403 said in Port from SW - Salt master rsa key issue:

                      I'm no salt expert (I've only played with it a few times) but just wanted to ask and confirm something about your RSA keys.

                      Are you entering a password when you generate the pairs or no?

                      No, I did not. I used "ssh-keygen -t rsa -C root@XXXX.com" (sensitive data redacted) as advised in a google search on the matter and chose to leave the password empty.

                      DustinB3403D 1 Reply Last reply Reply Quote 0
                      • DustinB3403D
                        DustinB3403 @dgingerich
                        last edited by

                        @dgingerich Hrm. . .

                        If you're just entering through the process I don't think it would be the RSA keys then . . . maybe there is a firewall enabled on your Masters/Minions?

                        scottalanmillerS D 2 Replies Last reply Reply Quote 0
                        • D
                          dgingerich @scottalanmiller
                          last edited by

                          @scottalanmiller said in Port from SW - Salt master rsa key issue:

                          @dgingerich said in Port from SW - Salt master rsa key issue:

                          @scottalanmiller It's a matter of the person putting the keys into the repository config.

                          We use GitLab, it's basically instant.

                          yeah, well, I'm not one of the ones making decisions on this project. I'm just setting up the QA stack. If I could, I would set it up entirely manually. It would take me less time. However, they want it exactly like prod except for the server numbers, and prod is too big to do manually.

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @DustinB3403
                            last edited by

                            @DustinB3403 said in Port from SW - Salt master rsa key issue:

                            @dgingerich Hrm. . .

                            If you're just entering through the process I don't think it would be the RSA keys then . . . maybe there is a firewall enabled on your Masters/Minions?

                            Given that it worked and the key regen broke it, it's safe to assume it's a key issue.

                            DustinB3403D 1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @dgingerich
                              last edited by

                              @dgingerich said in Port from SW - Salt master rsa key issue:

                              @scottalanmiller said in Port from SW - Salt master rsa key issue:

                              @dgingerich said in Port from SW - Salt master rsa key issue:

                              @scottalanmiller It's a matter of the person putting the keys into the repository config.

                              We use GitLab, it's basically instant.

                              yeah, well, I'm not one of the ones making decisions on this project. I'm just setting up the QA stack. If I could, I would set it up entirely manually. It would take me less time. However, they want it exactly like prod except for the server numbers, and prod is too big to do manually.

                              That's our prod 🙂

                              1 Reply Last reply Reply Quote 0
                              • D
                                dgingerich @DustinB3403
                                last edited by

                                @DustinB3403 said in Port from SW - Salt master rsa key issue:

                                @dgingerich Hrm. . .

                                If you're just entering through the process I don't think it would be the RSA keys then . . . maybe there is a firewall enabled on your Masters/Minions?

                                I haven't had the opportunity to do anything with the firewall to this point. By default, it is wide open.

                                scottalanmillerS 1 Reply Last reply Reply Quote 0
                                • DustinB3403D
                                  DustinB3403 @scottalanmiller
                                  last edited by

                                  @scottalanmiller said in Port from SW - Salt master rsa key issue:

                                  @DustinB3403 said in Port from SW - Salt master rsa key issue:

                                  @dgingerich Hrm. . .

                                  If you're just entering through the process I don't think it would be the RSA keys then . . . maybe there is a firewall enabled on your Masters/Minions?

                                  Given that it worked and the key regen broke it, it's safe to assume it's a key issue.

                                  I was under the assumption he replaced all of the keys.

                                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller @dgingerich
                                    last edited by

                                    @dgingerich said in Port from SW - Salt master rsa key issue:

                                    @DustinB3403 said in Port from SW - Salt master rsa key issue:

                                    @dgingerich Hrm. . .

                                    If you're just entering through the process I don't think it would be the RSA keys then . . . maybe there is a firewall enabled on your Masters/Minions?

                                    I haven't had the opportunity to do anything with the firewall to this point. By default, it is wide open.

                                    Ah, good ol' ubuntu.

                                    1 Reply Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller @DustinB3403
                                      last edited by

                                      @DustinB3403 said in Port from SW - Salt master rsa key issue:

                                      @scottalanmiller said in Port from SW - Salt master rsa key issue:

                                      @DustinB3403 said in Port from SW - Salt master rsa key issue:

                                      @dgingerich Hrm. . .

                                      If you're just entering through the process I don't think it would be the RSA keys then . . . maybe there is a firewall enabled on your Masters/Minions?

                                      Given that it worked and the key regen broke it, it's safe to assume it's a key issue.

                                      I was under the assumption he replaced all of the keys.

                                      Right, that is the break.

                                      1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller
                                        last edited by

                                        One of our big Salt users is @QuixoticJeremy and he is at the MangoMeetup event today.

                                        1 Reply Last reply Reply Quote 0
                                        • scottalanmillerS
                                          scottalanmiller
                                          last edited by

                                          I'm trying to research this, but this is definitely not a common issue.

                                          DanpD 1 Reply Last reply Reply Quote 0
                                          • DanpD
                                            Danp @scottalanmiller
                                            last edited by

                                            @scottalanmiller said in Port from SW - Salt master rsa key issue:

                                            I'm trying to research this, but this is definitely not a common issue.

                                            Perhaps he should contact vendor support?

                                            🙂

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 3 / 3
                                            • First post
                                              Last post