HW 2.6 Configure KMIP

Hi,

After KMIP server says “Starting KMIP server” on infrastructure, I ran the mongod syntax on database server but I got an error:-
2018-12-06T04:30:27.641+0000 E NETWORK [initandlisten] The server certificate does not match the host name XXX.XXX.XX.200
2018-12-06T04:30:27.642+0000 E STORAGE [initandlisten] Unable to retrieve key . system, error: Failed to open connection to KMIP server XXX.XXX.XX.200.
2018-12-06T04:30:27.644+0000 I - [initandlisten] Fatal Assertion 28561

In my mongod syntax, I passed the KMIP server’s IP address as hostname to the kmipServerName. I also tried to pass the bind_ip option for the database server’s IP address but it’s still not working.

I have all 3 certificates files from the m310-certs.zip file copied in the certs folder within shared folder. I noticed that the m310-hw-2.6.zip file also has 3 certificate files but I think they are the same.

I created db directory as well and passed it and mongod port number along with those kmip options shown in the lecture.

I pinged from database and from infrastructure and they are fine.

Not sure what I am missing. Maybe my KMIP server is not working but I think the error message below happened when I got the error running the mongod syntax on the database server?

2018-12-06 04:03:51,429 - main - INFO - Starting KMIP server
2018-12-06 04:06:37,534 - kmip.services.kmip_server - ERROR - KMIPServer <class ‘ssl.SSLEOFError’> EOF occurred in violation of protocol (_ssl.c:1783)

Please advise.

Thanks

Hi wini_mongo,

The error is likely from using the IP address for --kmipServerName instead of the FQDN.

The certificates being used contain the FQDN not the IP.

2018-12-06T04:30:27.641+0000 E NETWORK [initandlisten] The server certificate does not match the host name XXX.XXX.XX.200

Hope that helps,

David

2 Likes

Thank you so much! It worked. :slight_smile: