XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    NBD error SSL

    Scheduled Pinned Locked Moved Management
    13 Posts 2 Posters 441 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • andersonvazA Offline
      andersonvaz
      last edited by

      90a5e177-e040-4d56-b64c-b96127ab37ef-image.png

      I'm having trouble activating backup via NBD

      gskgerG 1 Reply Last reply Reply Quote 0
      • gskgerG Offline
        gskger Top contributor @andersonvaz
        last edited by

        @andersonvaz It probably makes sense to share more information on your setup (type of hosts and storage system, XCP-ng version, Xen Orchestra version, remotes and backup settings).

        1 Reply Last reply Reply Quote 0
        • andersonvazA Offline
          andersonvaz
          last edited by

          I use storage with NFS V3 - freenas
          5 Nodes xcp-ng 8.2.1
          XenOrchestra - https://github.com/vatesfr/xen-orchestra/commit/5b85a01d8340256271e75c9b4737e98dae3a656b
          Backup is running Continuous Replication to storage NFS V3 - Freenas

          0 julien-f committed to vatesfr/xen-orchestra
          docs: adapt logs access to new appliance
          gskgerG 1 Reply Last reply Reply Quote 0
          • gskgerG Offline
            gskger Top contributor @andersonvaz
            last edited by

            @andersonvaz Just to double check: Are your running the old FreeNAS (EOL October 2020) or a recent TrueNAS Core or Scale?

            andersonvazA 1 Reply Last reply Reply Quote 0
            • andersonvazA Offline
              andersonvaz @gskger
              last edited by

              @gskger TrueNAS CORE® © 2021 - iXsystems, Inc.

              gskgerG 1 Reply Last reply Reply Quote 0
              • gskgerG Offline
                gskger Top contributor @andersonvaz
                last edited by

                @andersonvaz Sounds a bit like either the host/XO or TrueNAS want's to talk SSL TLSv1.1 which is depriciated. What version of TrueNAS core are you runing? The latest 13.0-U6? Can you check the TLS Cipher settings on TrueNAS (System - General - HTTPS Protocolls)? Which cipher are enabled?

                andersonvazA 1 Reply Last reply Reply Quote 0
                • andersonvazA Offline
                  andersonvaz @gskger
                  last edited by

                  @gskger NBD communication would not be
                  xenorchestra -> XCP-NG -> NFS STORAGE ?
                  Therefore, xenorchestra does not have direct communication with TrueNas.

                  From what I saw, xenorchestra does not connect to XCP-NG

                  gskgerG 1 Reply Last reply Reply Quote 0
                  • gskgerG Offline
                    gskger Top contributor @andersonvaz
                    last edited by gskger

                    @andersonvaz All backups go through Xen Orchestra (have a look at the documentation on backups or the excellent YT video How To Use Xen Orchestra and XCP-NG To Backup and Restore Your Virtual Machines by @lawrencesystems.

                    XO or XOA is the central management tool to visualize, control, backup and manage your XCP-ng hosts and VMs. It must connect to the XCP-ng master host (read/write) to control it. XCP-ng slave hosts are in read only mode, "controlled" by the master hosts settings.

                    Edit: Backups can also go through Proxies on remote sites.

                    andersonvazA 2 Replies Last reply Reply Quote 0
                    • andersonvazA Offline
                      andersonvaz @gskger
                      last edited by

                      @gskger I've been using XCP-NG for a long time, but I didn't understand what you said about the certificate in relation to truenas https with NBD, since it would only be in XCP-NG.
                      This explanation you gave about the Truenas certificate is confusing because Truenas does not have NBD

                      gskgerG 1 Reply Last reply Reply Quote 0
                      • andersonvazA Offline
                        andersonvaz @gskger
                        last edited by

                        @gskger Do you use NBD?

                        gskgerG 1 Reply Last reply Reply Quote 0
                        • gskgerG Offline
                          gskger Top contributor @andersonvaz
                          last edited by

                          @andersonvaz I wouldn't call it "using NBD" yet because I'm experimenting with it in my playlab. However, the SSL_CTX_use_certificate:ee key too small error message suggest a TLS cipher problem and since the Xen Orchestra 5.76 blog post states that XO is using TLS by default, so the transfer is secure it might be related. According to that (older) post, you can disable TLS with "insecure NBD" for ruling this out.

                          But you are right, perhaps others who have more relevant experience with NBD can chime in to help.

                          1 Reply Last reply Reply Quote 0
                          • gskgerG Offline
                            gskger Top contributor @andersonvaz
                            last edited by

                            @andersonvaz said in NBD error SSL:

                            @gskger This explanation you gave about the Truenas certificate is confusing because Truenas does not have NBD

                            True, since NBD is the transfer method between the XCP-ng hosts and Xen Orchestra. Sorry for the confusion.

                            andersonvazA 1 Reply Last reply Reply Quote 0
                            • andersonvazA Offline
                              andersonvaz @gskger
                              last edited by

                              @gskger No problem, I just didn't understand the relationship with truenas' tls.
                              I'll wait to see if anyone else goes through this and in the meantime I'll continue my studies with nbd.
                              Thanks

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post