ONTAP S3 object store becomes unavailable due to 'certificate verify failed'
Applies to
- ONTAP S3
- ONTAP 9
Issue
- ONTAP S3 server is unavailable.
Thu Aug 11 12:51:15 -0400 [cluster1-01: OscLowPriThreadPool: object.store.unavailable:EMERGENCY]: Unable to connect to the object store "s3" from node db33b0cc-6790-11e9-8178-00a098fc9d58. Reason: Connection unavailable.
- VMs are not able to connect to the Cluster.
- Data servers and application servers unable to connect.
- No access to files with error:
Data can't be read to this file extension
- EMS shows one of these events:
ktlsd: ktls.failed:notice]: "The TLS connections have failed several times with remote host '123.45.67.89' in IPspace '4294967295', for which the latest reason given is: OpenSSL: error:0A000086:SSL routines::certificate verify failed."
ktlsd: ktls.failed:notice]: "The TLS connections have failed several times with remote host '123.45.67.89' in IPspace '4294967295', for which the latest reason given is: OpenSSL: error:0A000415:SSL routines::sslv3 alert certificate expired."
