Re: can't get rhn_register (and therefore client s) working

Hunter Matthews <[email protected]>
Newsgroups gmane.network.up2date.current.devel
Message-ID <1019845837.1700.540.camel@kea>
I will try to remember and add a "Does rhn_register work from the server
itself? If yes, you have ipchains/wrappers issues." to the FAQ as well.


On Fri, 2002-04-26 at 13:18, Ryan Speed wrote:
> Finally I have made some headway.  It was a key issue (2 seperate issues really).  I started stunnel and set it so it wouldnt daemonise.
> 
> First off it didn't like 644 for permissions on /etc/current/current.pem I set them to 600 but still had a problem;
> 
> the output from stunnel -d 8081 -r 8080 -p /etc/current/current.pem -f was as follows:
> 
> [root@lada root]# stunnel -d 8081 -r 8080 -p /etc/current/current.pem -f
> 2002.04.26 10:10:58 LOG5[22972:1024]: Using '8080' as tcpwrapper service name
> 2002.04.26 10:10:58 LOG5[22972:1024]: stunnel 3.22 on i386-redhat-linux-gnu PTHREAD+LIBWRAP with OpenSSL 0.9.6b [engine] 9 Jul 2001
> 2002.04.26 10:10:58 LOG5[22972:1024]: FD_SETSIZE=1024, file ulimit=1024 -> 500 clients allowed
> 2002.04.26 10:11:28 LOG4[23011:1026]: Connection from 10.100.0.205:32992 REFUSED by libwrap
> 
> Bingo, stunnel uses tcpwrappers, I feel foolish now knowing that all I had to do was add a simple entry to the /etc/hosts.allow file
> 
> 8080:		network/subnet
> 
> I got the 8080 from this "Using '8080' as tcpwrapper service name"
> 
> I can now connect manually with 
> 
> openssl s_client -connect lada:8081 -verify /usr/share/rhn/RHNS-CA-CERT
> 
> and rhn_register also works no problem.
> 
> I'm not too sure if this is a FAQ, if it isn't it probably should as in redhat 7.2 stunnel is compiled with PTHREAD+LIBWRAP by default (as far as I know.  This box is a stock redhat machine with the latest udates).
> 
> I'd like to thank you all for your help, I'm feeling pretty newbish right now ;)
> 
> thanks,
> ryan
> 
> On Fri, 26 Apr 2002 09:04:57 +0100
> [email protected] wrote:
> 
> > 
> > Doh wrong again, sorry shouldn't post without checking
> > 
> > Hunter this is correct AFAIIK for the faq, plus could you put the FAQ on
> > the website as well.
> > 
> > _______________________________________________
> > Current-server mailing list
> > [email protected]
> > http://lists.dulug.duke.edu/mailman/listinfo/current-server
> _______________________________________________
> Current-server mailing list
> [email protected]
> http://lists.dulug.duke.edu/mailman/listinfo/current-server
> 
> 
-- 
Hunter Matthews                          Unix / Network Administrator
Office: BioScience 145/244               Duke Univ. Biology Department
Key: F0F88438 / FFB5 34C0 B350 99A4 BB02  9779 A5DB 8B09 F0F8 8438
Never take candy from strangers. Especially on the internet.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.