stejzyy23

Untitled

Jul 1st, 2020
71
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 6.77 KB | None | 0 0
  1. Error ve /var/log/foreman-proxy/smart_proxy_dynflow_core.log
  2.  
  3. 192.168.121.3 - - [01/Jul/2020:15:22:34 UTC] "POST /tasks/launch? HTTP/1.1" 200 110
  4. 403 Forbidden (RestClient::Forbidden)
  5. /opt/theforeman/tfm/root/usr/share/gems/gems/rest-client-2.0.2/lib/restclient/abstract_response.rb:223:in `excepti
  6. on_with_response'
  7. /opt/theforeman/tfm/root/usr/share/gems/gems/rest-client-2.0.2/lib/restclient/abstract_response.rb:103:in `return!
  8. '
  9. /opt/theforeman/tfm/root/usr/share/gems/gems/rest-client-2.0.2/lib/restclient/request.rb:809:in `process_result'
  10. /opt/theforeman/tfm/root/usr/share/gems/gems/rest-client-2.0.2/lib/restclient/request.rb:725:in `block in transmit
  11. '
  12. /opt/rh/rh-ruby25/root/usr/share/ruby/net/http.rb:910:in `start'
  13. /opt/theforeman/tfm/root/usr/share/gems/gems/rest-client-2.0.2/lib/restclient/request.rb:715:in `transmit'
  14. /opt/theforeman/tfm/root/usr/share/gems/gems/rest-client-2.0.2/lib/restclient/request.rb:145:in `execute'
  15. /opt/theforeman/tfm/root/usr/share/gems/gems/rest-client-2.0.2/lib/restclient/request.rb:52:in `execute'
  16. /opt/theforeman/tfm/root/usr/share/gems/gems/rest-client-2.0.2/lib/restclient/resource.rb:67:in `post'
  17. /opt/theforeman/tfm/root/usr/share/gems/gems/smart_proxy_dynflow_core-0.2.6/lib/smart_proxy_dynflow_core/callback.
  18. rb:51:in `callback'
  19.  
  20.  
  21. Nebo foreman log, chyb jako tahle je tam spousta:
  22.  
  23.  
  24. 08:34:56 rails.1 | 2020-07-02T08:34:56 [I|app|8ff2b68f] Started POST "/api/config_reports" for 127.0.0.1 at 2020-07-02 08:34:56 +0000
  25. 08:34:56 rails.1 | 2020-07-02T08:34:56 [I|app|8ff2b68f] Processing by Api::V2::ConfigReportsController#create as JSON
  26. 08:34:56 rails.1 | 2020-07-02T08:34:56 [I|app|8ff2b68f] Parameters: {"config_report"=>"[FILTERED]", "apiv"=>"v2"}
  27. 08:34:56 rails.1 | 2020-07-02T08:34:56 [W|app|8ff2b68f] No SSL cert with CN supplied - request from 192.168.121.3
  28. 08:34:56 rails.1 | 2020-07-02T08:34:56 [I|app|8ff2b68f] Rendering api/v2/errors/access_denied.json.rabl within api/v2/layouts/error_layout
  29. 08:34:56 rails.1 | 2020-07-02T08:34:56 [I|app|8ff2b68f] Rendered api/v2/errors/access_denied.json.rabl within api/v2/layouts/error_layout (Duration: 4.6ms | Allocations: 6339)
  30. 08:34:56 rails.1 | 2020-07-02T08:34:56 [I|app|8ff2b68f] Filter chain halted as #<Proc:0x00000000115d5be0@/home/vagrant/foreman/app/controllers/concerns/foreman/controller/smart_proxy_auth.rb:14> rendered or redirected
  31. 08:34:56 rails.1 | 2020-07-02T08:34:56 [I|app|8ff2b68f] Completed 403 Forbidden in 22ms (Views: 10.2ms | ActiveRecord: 4.2ms | Allocations: 16559)
  32.  
  33.  
  34. ------------------------------------------------------------------------------------------------
  35. ------------------------------------------------------------------------------------------------
  36. ------------------------------------------------------------------------------------------------
  37. cat /etc/smart_proxy_dynflow_core/settings.yml
  38. # Path to dynflow database, leave blank for in-memory non-persistent database
  39. :database:
  40. :console_auth: true
  41.  
  42. # URL of the foreman, used for reporting back
  43. :foreman_url: https://centos7-luna-devel.notas.example.com
  44.  
  45. # SSL settings for client authentication against foreman.
  46. :foreman_ssl_ca: /etc/foreman-proxy/foreman_ssl_ca.pem
  47. :foreman_ssl_cert: /etc/foreman-proxy/foreman_ssl_cert.pem
  48. :foreman_ssl_key: /etc/foreman-proxy/foreman_ssl_key.pem
  49.  
  50. # Listen on address
  51. :listen: "*"
  52.  
  53. # Listen on port
  54. :port: 8008
  55.  
  56. :use_https: true
  57. :ssl_ca_file: /etc/foreman-proxy/ssl_ca.pem
  58. :ssl_certificate: /etc/foreman-proxy/ssl_cert.pem
  59. :ssl_private_key: /etc/foreman-proxy/ssl_key.pem
  60. # :ssl_ca_file: ssl/ca.pem
  61. # :ssl_private_key: ssl/localhost.pem
  62. # :ssl_certificate: ssl/certs/localhost.pem
  63.  
  64. # Use this option only if you need to disable certain cipher suites.
  65. # Note: we use the OpenSSL suite name, take a look at:
  66. # https://www.openssl.org/docs/manmaster/apps/ciphers.html#CIPHER-SUITE-NAMES
  67. # for more information.
  68. #:ssl_disabled_ciphers: [CIPHER-SUITE-1, CIPHER-SUITE-2]
  69.  
  70. # Use this option only if you need to strictly specify TLS versions to be
  71. # disabled. SSLv3 and TLS v1.0 are always disabled and cannot be configured.
  72. # Specify versions like: '1.1', or '1.2'
  73. #:tls_disabled_versions: []
  74.  
  75. # File to log to, leave empty for logging to STDOUT
  76. :log_file: /var/log/foreman-proxy/smart_proxy_dynflow_core.log
  77.  
  78. # Log level, one of UNKNOWN, FATAL, ERROR, WARN, INFO, DEBUG
  79. :log_level: ERROR
  80.  
  81.  
  82. ------------------------------------------------------------------------------------------------
  83. ------------------------------------------------------------------------------------------------
  84. cat /etc/foreman-proxy/settings.yml
  85. ---
  86. ### File managed with puppet ###
  87. ## Module: 'foreman_proxy'
  88.  
  89. :settings_directory: /etc/foreman-proxy/settings.d
  90.  
  91. # SSL Setup
  92.  
  93. # if enabled, all communication would be verified via SSL
  94. # NOTE that both certificates need to be signed by the same CA in order for this to work
  95. # see http://theforeman.org/projects/smart-proxy/wiki/SSL for more information
  96. :ssl_ca_file: /etc/foreman-proxy/ssl_ca.pem
  97. :ssl_certificate: /etc/foreman-proxy/ssl_cert.pem
  98. :ssl_private_key: /etc/foreman-proxy/ssl_key.pem
  99.  
  100. # Use this option only if you need to disable certain cipher suites.
  101. # Note: we use the OpenSSL suite name, such as "RC4-MD5".
  102. # The complete list of cipher suite names can be found at:
  103. # https://www.openssl.org/docs/manmaster/man1/ciphers.html#CIPHER-SUITE-NAMES
  104. #:ssl_disabled_ciphers: [CIPHER-SUITE-1, CIPHER-SUITE-2]
  105.  
  106. # Use this option only if you need to strictly specify TLS versions to be
  107. # disabled. SSLv3 and TLS v1.0 are always disabled and cannot be configured.
  108. # Specify versions like: '1.1', or '1.2'
  109. #:tls_disabled_versions: []
  110.  
  111. # the hosts which the proxy accepts connections from
  112. # commenting the following lines would mean every verified SSL connection allowed
  113. :trusted_hosts:
  114. - centos7-luna-devel.notas.example.com
  115.  
  116. # Endpoint for reverse communication
  117. :foreman_url: https://centos7-luna-devel.notas.example.com
  118.  
  119. # SSL settings for client authentication against Foreman. If undefined, the values
  120. # from general SSL options are used instead. Mainly useful when Foreman uses
  121. # different certificates for its web UI and for smart-proxy requests.
  122. :foreman_ssl_ca: /etc/foreman-proxy/foreman_ssl_ca.pem
  123. :foreman_ssl_cert: /etc/foreman-proxy/foreman_ssl_cert.pem
  124. :foreman_ssl_key: /etc/foreman-proxy/foreman_ssl_key.pem
  125.  
  126. # by default smart_proxy runs in the foreground. To enable running as a daemon, uncomment 'daemon' setting
  127. :daemon: true
  128. # Only used when 'daemon' is set to true.
  129. # Uncomment and modify if you want to change the default pid file '/var/run/foreman-proxy/foreman-proxy.pid'
  130. #:daemon_pid: /var/run/foreman-proxy/foreman-proxy.pid
  131.  
  132. # host and ports configuration
  133. # Host or IP to bind ports to (e.g. *, localhost, 0.0.0.0, ::, 192.168.1.20)
  134. :bind_host: '*'
  135. # http is disabled by default. To enable, uncomment 'http_port' setting
  136. # https is enabled if certificate, CA certificate, and private key are present in locations specifed by
  137. # ssl_certificate, ssl_ca_file, and ssl_private_key correspondingly
  138. # default values for https_port is 8443
  139. :https_port: 9090
  140. :http_port: 8000
  141. # Log configuration
  142. # Uncomment and modify if you want to change the location of the log file or use STDOUT or SYSLOG values
  143. :log_file: /var/log/foreman-proxy/proxy.log
  144. # Uncomment and modify if you want to change the log level
  145. # WARN, DEBUG, ERROR, FATAL, INFO, UNKNOWN
  146. :log_level: DEBUG
  147. # The maximum size of a log file before it's rolled (in MiB)
  148. #:file_rolling_size: 100
  149. # The maximum age of a log file before it's rolled (in seconds). Also accepts 'daily', 'weekly', or 'monthly'.
  150. #:file_rolling_age: weekly
  151. # Number of log files to keep
  152. #:file_rolling_keep: 6
  153. # Logging pattern for file-based loging
  154. #:file_logging_pattern: '%d %.8X{request} [%.1l] %m'
  155. # Logging pattern for syslog or journal loging
  156. #:system_logging_pattern: '%.8X{request} [%.1l] %m'
  157.  
  158.  
  159. # Log buffer size and extra buffer size (for errors). Defaults to 3000 messages in total,
  160. # which is about 500 kB request.
  161. :log_buffer: 2000
  162. :log_buffer_errors: 1000
Add Comment
Please, Sign In to add comment