Skip to main content
NetApp Knowledge Base

Unable to create cluster peer relationships due to missing PSK and GCM security ciphers

Views:
283
Visibility:
Public
Votes:
0
Category:
snapmirror
Specialty:
dp
Last Updated:

Applies to

  • ONTAP 9.6+
  • Cluster Peer
  • Pre-Shared Key (PSK) cipher suites

Issue

  • Cluster Peering stopped working and all new configuration attempts fail after removing  weak cipher suites.

Warning in EMS logs:
 
Wed Apr 12 11:14:23 +0100 [node-01: mgwd: cpeer.psk.disabled:notice]: The system was unable to find a suitable pre-shared key (PSK) cipher suite required for cluster peering. This is likely because the PSK cipher suites are disabled in the ONTAP security configuration. Cluster peering connections and associated applications may fail as a result.

  • Attempts to create a cluster peer fail with the below error message:

Error: command failed: Using peer-address XX.XXX.XX.X: An introductory RPC to the peer address "XX.XX.XX.XX" failed to connect: RPC: Remote system error [from mgwd on node "XXXXXXXXX" (VSID: -1) to xcintro at XX.XX.XX.XX].  Verify that the peer address is correct and try again

  • MGWD log messages located in /etc/log/mlog/mgwd.log report error messages about missing Pre-Shared Key (PSK) cipher suites.

Mon Jul 13 2020 12:58:30 +05:30 [kern_mgwd:info:1668] 0x81b004200: 0: ERR: mgwdmain: set_xc_dsmdb_rpc_services: called
Mon Jul 13 2020 12:58:30 +05:30 [kern_mgwd:info:1668] 0x81b004200: 0: NOTICE: RpcConnectionCache: SetUpSslOps: Set up SSL ops.
Mon Jul 13 2020 12:58:30 +05:30 [kern_mgwd:info:1668] 0x81b004200: 0: ERR: RpcConnectionCache: getXcContext: Could not find any PSK cipher suites (0).
Mon Jul 13 2020 12:58:30 +05:30 [kern_mgwd:info:1668] 0x81b004200: 0: ERR: RpcConnectionCache: SetUpTlsConnections: Could not get a client SSL context.

  • Cluster peer show  output reports the availability of the Remote Cluster as Unavailable.
    • Cluster peer health show is empty:
      ::> cluster peer health show
      This table is currently empty
  • When the required cipher is missing from a cluster, it stops listening on tcp port 11104
    • No response on Port 11104:
      ::*> system node systemshell -node Node_A1 nc -zv 10.XX.XX.3 11104
      nc: connect to 10.XX.XX.3 port 11104 (tcp) failed: Connection refused.

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.