Re: TLS Certificate Registration Problem
"Kaplan, Michael A" <[email protected]> Tue, 30 Nov 2010 17:24:37 -0500
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <563593148DD9A040B93397F642B3C12558C53383A0@rrc-dte-exmb1.dte.telcordia.com> |
Yes this was the problem. Thank you. -----Original Message----- From: Pierre Chifflier [mailto:[email protected]] Sent: Tuesday, November 30, 2010 2:48 PM To: Kaplan, Michael A Cc: [email protected] Subject: Re: [prelude-devel] TLS Certificate Registration Problem On Tue, Nov 30, 2010 at 12:18:34PM -0500, Kaplan, Michael A wrote: > I am installing Prelude-Manager and Snort on some FC14 machines. > Prelude Manager runs on one server, snort runs on all servers. I am > having trouble connecting the remote snort sensors to the central > prelude manager. I perform the TLS registration process, and in the > end I see the "Authentication Succeeded" and "Sensor Successfully > Registered" messages. So everything at first seems fine. > > However, then when I actually run the sensor (snort), I get "Error: > prelude-client: Unable to initialize prelude client: TLSserver > certificate is not yet activated". At the Prelude Manager I see "TLS > fatal alert from peer: Certificate is bad." The sensor asks me to > rerun prelude-admin register...etc. since "profile does not exist." I > tried rerunning this command, copying and pasting the requested > command. Hi, 'certificate is not yet activated' is probably caused by a difference in the time reference for the snort host and the prelude manager. Are the servers synchronized ? Using NTP would be a good idea. HTH, Pierre > > I have done this set up before (though with FC12) and things worked > just fine. Any suggestions? > > Mike _______________________________________________ Prelude-devel site list [email protected] http://lists.prelude-technologies.com/mailman/listinfo/prelude-devel