Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Error ve /var/log/foreman-proxy/smart_proxy_dynflow_core.log
- 192.168.121.3 - - [01/Jul/2020:15:22:34 UTC] "POST /tasks/launch? HTTP/1.1" 200 110
- 403 Forbidden (RestClient::Forbidden)
- /opt/theforeman/tfm/root/usr/share/gems/gems/rest-client-2.0.2/lib/restclient/abstract_response.rb:223:in `excepti
- on_with_response'
- /opt/theforeman/tfm/root/usr/share/gems/gems/rest-client-2.0.2/lib/restclient/abstract_response.rb:103:in `return!
- '
- /opt/theforeman/tfm/root/usr/share/gems/gems/rest-client-2.0.2/lib/restclient/request.rb:809:in `process_result'
- /opt/theforeman/tfm/root/usr/share/gems/gems/rest-client-2.0.2/lib/restclient/request.rb:725:in `block in transmit
- '
- /opt/rh/rh-ruby25/root/usr/share/ruby/net/http.rb:910:in `start'
- /opt/theforeman/tfm/root/usr/share/gems/gems/rest-client-2.0.2/lib/restclient/request.rb:715:in `transmit'
- /opt/theforeman/tfm/root/usr/share/gems/gems/rest-client-2.0.2/lib/restclient/request.rb:145:in `execute'
- /opt/theforeman/tfm/root/usr/share/gems/gems/rest-client-2.0.2/lib/restclient/request.rb:52:in `execute'
- /opt/theforeman/tfm/root/usr/share/gems/gems/rest-client-2.0.2/lib/restclient/resource.rb:67:in `post'
- /opt/theforeman/tfm/root/usr/share/gems/gems/smart_proxy_dynflow_core-0.2.6/lib/smart_proxy_dynflow_core/callback.
- rb:51:in `callback'
- Nebo foreman log, chyb jako tahle je tam spousta:
- 08:34:56 rails.1 | 2020-07-02T08:34:56 [I|app|8ff2b68f] Started POST "/api/config_reports" for 127.0.0.1 at 2020-07-02 08:34:56 +0000
- 08:34:56 rails.1 | 2020-07-02T08:34:56 [I|app|8ff2b68f] Processing by Api::V2::ConfigReportsController#create as JSON
- 08:34:56 rails.1 | 2020-07-02T08:34:56 [I|app|8ff2b68f] Parameters: {"config_report"=>"[FILTERED]", "apiv"=>"v2"}
- 08:34:56 rails.1 | 2020-07-02T08:34:56 [W|app|8ff2b68f] No SSL cert with CN supplied - request from 192.168.121.3
- 08:34:56 rails.1 | 2020-07-02T08:34:56 [I|app|8ff2b68f] Rendering api/v2/errors/access_denied.json.rabl within api/v2/layouts/error_layout
- 08:34:56 rails.1 | 2020-07-02T08:34:56 [I|app|8ff2b68f] Rendered api/v2/errors/access_denied.json.rabl within api/v2/layouts/error_layout (Duration: 4.6ms | Allocations: 6339)
- 08:34:56 rails.1 | 2020-07-02T08:34:56 [I|app|8ff2b68f] Filter chain halted as #<Proc:0x00000000115d5be0@/home/vagrant/foreman/app/controllers/concerns/foreman/controller/smart_proxy_auth.rb:14> rendered or redirected
- 08:34:56 rails.1 | 2020-07-02T08:34:56 [I|app|8ff2b68f] Completed 403 Forbidden in 22ms (Views: 10.2ms | ActiveRecord: 4.2ms | Allocations: 16559)
- ------------------------------------------------------------------------------------------------
- ------------------------------------------------------------------------------------------------
- ------------------------------------------------------------------------------------------------
- cat /etc/smart_proxy_dynflow_core/settings.yml
- # Path to dynflow database, leave blank for in-memory non-persistent database
- :database:
- :console_auth: true
- # URL of the foreman, used for reporting back
- :foreman_url: https://centos7-luna-devel.notas.example.com
- # SSL settings for client authentication against foreman.
- :foreman_ssl_ca: /etc/foreman-proxy/foreman_ssl_ca.pem
- :foreman_ssl_cert: /etc/foreman-proxy/foreman_ssl_cert.pem
- :foreman_ssl_key: /etc/foreman-proxy/foreman_ssl_key.pem
- # Listen on address
- :listen: "*"
- # Listen on port
- :port: 8008
- :use_https: true
- :ssl_ca_file: /etc/foreman-proxy/ssl_ca.pem
- :ssl_certificate: /etc/foreman-proxy/ssl_cert.pem
- :ssl_private_key: /etc/foreman-proxy/ssl_key.pem
- # :ssl_ca_file: ssl/ca.pem
- # :ssl_private_key: ssl/localhost.pem
- # :ssl_certificate: ssl/certs/localhost.pem
- # Use this option only if you need to disable certain cipher suites.
- # Note: we use the OpenSSL suite name, take a look at:
- # https://www.openssl.org/docs/manmaster/apps/ciphers.html#CIPHER-SUITE-NAMES
- # for more information.
- #:ssl_disabled_ciphers: [CIPHER-SUITE-1, CIPHER-SUITE-2]
- # Use this option only if you need to strictly specify TLS versions to be
- # disabled. SSLv3 and TLS v1.0 are always disabled and cannot be configured.
- # Specify versions like: '1.1', or '1.2'
- #:tls_disabled_versions: []
- # File to log to, leave empty for logging to STDOUT
- :log_file: /var/log/foreman-proxy/smart_proxy_dynflow_core.log
- # Log level, one of UNKNOWN, FATAL, ERROR, WARN, INFO, DEBUG
- :log_level: ERROR
- ------------------------------------------------------------------------------------------------
- ------------------------------------------------------------------------------------------------
- cat /etc/foreman-proxy/settings.yml
- ---
- ### File managed with puppet ###
- ## Module: 'foreman_proxy'
- :settings_directory: /etc/foreman-proxy/settings.d
- # SSL Setup
- # if enabled, all communication would be verified via SSL
- # NOTE that both certificates need to be signed by the same CA in order for this to work
- # see http://theforeman.org/projects/smart-proxy/wiki/SSL for more information
- :ssl_ca_file: /etc/foreman-proxy/ssl_ca.pem
- :ssl_certificate: /etc/foreman-proxy/ssl_cert.pem
- :ssl_private_key: /etc/foreman-proxy/ssl_key.pem
- # Use this option only if you need to disable certain cipher suites.
- # Note: we use the OpenSSL suite name, such as "RC4-MD5".
- # The complete list of cipher suite names can be found at:
- # https://www.openssl.org/docs/manmaster/man1/ciphers.html#CIPHER-SUITE-NAMES
- #:ssl_disabled_ciphers: [CIPHER-SUITE-1, CIPHER-SUITE-2]
- # Use this option only if you need to strictly specify TLS versions to be
- # disabled. SSLv3 and TLS v1.0 are always disabled and cannot be configured.
- # Specify versions like: '1.1', or '1.2'
- #:tls_disabled_versions: []
- # the hosts which the proxy accepts connections from
- # commenting the following lines would mean every verified SSL connection allowed
- :trusted_hosts:
- - centos7-luna-devel.notas.example.com
- # Endpoint for reverse communication
- :foreman_url: https://centos7-luna-devel.notas.example.com
- # SSL settings for client authentication against Foreman. If undefined, the values
- # from general SSL options are used instead. Mainly useful when Foreman uses
- # different certificates for its web UI and for smart-proxy requests.
- :foreman_ssl_ca: /etc/foreman-proxy/foreman_ssl_ca.pem
- :foreman_ssl_cert: /etc/foreman-proxy/foreman_ssl_cert.pem
- :foreman_ssl_key: /etc/foreman-proxy/foreman_ssl_key.pem
- # by default smart_proxy runs in the foreground. To enable running as a daemon, uncomment 'daemon' setting
- :daemon: true
- # Only used when 'daemon' is set to true.
- # Uncomment and modify if you want to change the default pid file '/var/run/foreman-proxy/foreman-proxy.pid'
- #:daemon_pid: /var/run/foreman-proxy/foreman-proxy.pid
- # host and ports configuration
- # Host or IP to bind ports to (e.g. *, localhost, 0.0.0.0, ::, 192.168.1.20)
- :bind_host: '*'
- # http is disabled by default. To enable, uncomment 'http_port' setting
- # https is enabled if certificate, CA certificate, and private key are present in locations specifed by
- # ssl_certificate, ssl_ca_file, and ssl_private_key correspondingly
- # default values for https_port is 8443
- :https_port: 9090
- :http_port: 8000
- # Log configuration
- # Uncomment and modify if you want to change the location of the log file or use STDOUT or SYSLOG values
- :log_file: /var/log/foreman-proxy/proxy.log
- # Uncomment and modify if you want to change the log level
- # WARN, DEBUG, ERROR, FATAL, INFO, UNKNOWN
- :log_level: DEBUG
- # The maximum size of a log file before it's rolled (in MiB)
- #:file_rolling_size: 100
- # The maximum age of a log file before it's rolled (in seconds). Also accepts 'daily', 'weekly', or 'monthly'.
- #:file_rolling_age: weekly
- # Number of log files to keep
- #:file_rolling_keep: 6
- # Logging pattern for file-based loging
- #:file_logging_pattern: '%d %.8X{request} [%.1l] %m'
- # Logging pattern for syslog or journal loging
- #:system_logging_pattern: '%.8X{request} [%.1l] %m'
- # Log buffer size and extra buffer size (for errors). Defaults to 3000 messages in total,
- # which is about 500 kB request.
- :log_buffer: 2000
- :log_buffer_errors: 1000
Add Comment
Please, Sign In to add comment