Re: TLS Certificate Registration Problem

Pierre Chifflier <[email protected]> Tue, 30 Nov 2010 20:48:16 +0100
Newsgroups gmane.comp.security.ids.prelude.devel
Organization EdenWall Technologies
Message-ID <[email protected]>
On Tue, Nov 30, 2010 at 12:18:34PM -0500, Kaplan, Michael A wrote:
> I am installing Prelude-Manager and Snort on some FC14 machines.
> Prelude Manager runs on one server, snort runs on all servers. I am
> having trouble connecting the remote snort sensors to the central
> prelude manager. I perform the TLS registration process, and in the
> end I see the "Authentication Succeeded" and "Sensor Successfully
> Registered" messages. So everything at first seems fine.
> 
> However, then when I actually run the sensor (snort), I get "Error:
> prelude-client: Unable to initialize prelude client: TLSserver
> certificate is not yet activated". At the Prelude Manager I see "TLS
> fatal alert from peer: Certificate is bad." The sensor asks me to
> rerun prelude-admin register...etc. since "profile does not exist." I
> tried rerunning this command, copying and pasting the requested
> command.

Hi,

'certificate is not yet activated' is probably caused by a difference in
the time reference for the snort host and the prelude manager. Are the
servers synchronized ? Using NTP would be a good idea.

HTH,
Pierre

> 
> I have done this set up before (though with FC12) and things worked
> just fine. Any suggestions?
> 
> Mike
_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-technologies.com/mailman/listinfo/prelude-devel