Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received. #21658

Open
masvild opened this issue Feb 27, 2025 · 1 comment
Open
Labels
bug question Further information is requested

Comments

@masvild
Copy link

masvild commented Feb 27, 2025

Explain what happens

  1. Feb 27 03:00:05 kvmserver sudo[67471]: pam_unix(sudo:session): session opened for user root by root(uid=0)
    Feb 27 03:00:05 kvmserver sudo[67471]: pam_unix(sudo:session): session closed for user root
    Feb 27 03:00:12 kvmserver sudo[67475]: root : TTY=pts/0 ; PWD=/root ; USER=root ; COMMAND=/bin/systemctl start cockpit.socket
    Feb 27 03:00:12 kvmserver sudo[67475]: pam_unix(sudo:session): session opened for user root by root(uid=0)
    Feb 27 03:00:12 kvmserver systemd[1]: Starting Cockpit motd updater service...
    Feb 27 03:00:12 kvmserver sudo[67475]: pam_unix(sudo:session): session closed for user root
    Feb 27 03:00:12 kvmserver systemd[1]: cockpit-motd.service: Succeeded.
    Feb 27 03:00:12 kvmserver systemd[1]: Started Cockpit motd updater service.
    Feb 27 03:00:17 kvmserver sudo[67490]: root : TTY=pts/0 ; PWD=/root ; USER=root ; COMMAND=/bin/journalctl -f
    Feb 27 03:00:17 kvmserver sudo[67490]: pam_unix(sudo:session): session opened for user root by root(uid=0)
    Feb 27 03:00:37 kvmserver systemd[1]: Starting Socket for Cockpit Web Service http instance.
    Feb 27 03:00:37 kvmserver systemd[1]: Starting Socket for Cockpit Web Service https instance factory.
    Feb 27 03:00:37 kvmserver systemd[1]: Listening on Socket for Cockpit Web Service http instance.
    Feb 27 03:00:37 kvmserver systemd[1]: Listening on Socket for Cockpit Web Service https instance factory.
    Feb 27 03:00:37 kvmserver systemd[1]: Starting Cockpit Web Service...
    Feb 27 03:00:37 kvmserver systemd[1]: Started Cockpit Web Service.
    Feb 27 03:00:40 kvmserver cockpit-tls[67499]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
    Feb 27 03:00:40 kvmserver cockpit-tls[67499]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
    Feb 27 03:00:49 kvmserver systemd[1]: Started Cockpit Web Service https instance factory (PID 67499/UID 987).
    Feb 27 03:00:49 kvmserver systemd[1]: Starting Socket for Cockpit Web Service https instance e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855.
    Feb 27 03:00:49 kvmserver systemd[1]: Listening on Socket for Cockpit Web Service https instance e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855.
    Feb 27 03:00:49 kvmserver systemd[1]: Started Cockpit Web Service https instance e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855.
    Feb 27 03:00:49 kvmserver systemd[1]: [email protected]: Succeeded.
    Feb 27 03:01:01 kvmserver CROND[67522]: (root) CMD (run-parts /etc/cron.hourly)
    Feb 27 03:01:01 kvmserver run-parts[67525]: (/etc/cron.hourly) starting 0anacron
    Feb 27 03:01:01 kvmserver anacron[67531]: Anacron started on 2025-02-27
    Feb 27 03:01:01 kvmserver anacron[67531]: Will run job `cron.daily' in 26 min.
    Feb 27 03:01:01 kvmserver anacron[67531]: Jobs will be executed sequentially
    Feb 27 03:01:01 kvmserver run-parts[67533]: (/etc/cron.hourly) finished 0anacron
    Feb 27 03:01:03 kvmserver cockpit-session[67534]: pam_ssh_add: Failed adding some keys
    Feb 27 03:01:03 kvmserver systemd-logind[1212]: New session 19 of user root.
    Feb 27 03:01:03 kvmserver systemd[1]: Started Session 19 of user root.
    Feb 27 03:01:03 kvmserver cockpit-session[67534]: pam_unix(cockpit:session): session opened for user root by (uid=0)
    Feb 27 03:01:03 kvmserver cockpit-ws[67542]: invalid or unusable locale: ru.UTF-8
    Feb 27 03:01:13 kvmserver cockpit-tls[67499]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
    Feb 27 03:01:13 kvmserver cockpit-tls[67499]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
    Feb 27 03:01:13 kvmserver cockpit-tls[67499]: cockpit-tls: gnutls_handshake failed: A TLS fatal alert has been received.
    Feb 27 03:01:18 kvmserver cockpit-session[67534]: pam_unix(cockpit:session): session closed for user root
    Feb 27 03:01:18 kvmserver systemd-logind[1212]: Session 19 logged out. Waiting for processes to exit.
    Feb 27 03:01:18 kvmserver systemd[1]: session-19.scope: Succeeded.
    Feb 27 03:01:18 kvmserver systemd-logind[1212]: Removed session 19.
    Feb 27 03:02:33 kvmserver systemd[1]: cockpit-wsinstance-https@e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855.service: Succeeded.
    Feb 27 03:02:33 kvmserver systemd[1]: cockpit-wsinstance-https@e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855.socket: Succeeded.
    Feb 27 03:02:33 kvmserver systemd[1]: Closed Socket for Cockpit Web Service https instance e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855.
    Feb 27 03:03:16 kvmserver systemd[1]: cockpit.service: Succeeded.
    Feb 27 03:03:16 kvmserver systemd[1]: cockpit-wsinstance-https-factory.socket: Succeeded.
    Feb 27 03:03:16 kvmserver systemd[1]: Closed Socket for Cockpit Web Service https instance factory.
    Feb 27 03:03:16 kvmserver systemd[1]: cockpit-wsinstance-http.socket: Succeeded.
    Feb 27 03:03:16 kvmserver systemd[1]: Closed Socket for Cockpit Web Service http instance.

Version of Cockpit

No response

Where is the problem in Cockpit?

None

Server operating system

CentOS

Server operating system version

8

What browsers are you using?

Chrome

System log

@masvild masvild added the bug label Feb 27, 2025
@martinpitt martinpitt added the question Further information is requested label Feb 27, 2025
@martinpitt
Copy link
Member

What are you trying to do and what failed? If you didn't give cockpit a proper certificate, then it will create a self-signed one and you will always get an initial TLS error when the browser rejects the unknown certificate and asks you about it. So far this is fully expected, and you didn't describe any actual error.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug question Further information is requested
Projects
None yet
Development

No branches or pull requests

2 participants