"Unable to get subsection" error with RC-4
-
@Psycholiquid Don’t leave out @testers, @moderators and in general the users.
-
@Psycholiquid said in "Unable to get subsection" error with RC-4:
@Bob-Henderson I have a group setup with all hosts in it and hit reset encryption there is I need to do for all. It is a quick and dirty way to do it.
Not even quick and dirty. This is the recommended way to do it.
-
@Tom-Elliott Adding more info: Net 4.5.1 is included in my image (WIN 7 x64), I redeployed to host, verified, restarted for good measure. No change in snapin deployment, the error persists. Updated logs below.
@Wayne-Workman I did attempt to reset encryption on the host via Groups, 192.168.35.155 is my machine, and I think that’s what is showing in the Apache error logs. May not be related, but in searching past post on this error the Apache logs were posted and I wanted to include is as much info as I could. Let me know if more of that log would be helpful.
------------------------------------------------------------------------------ --------------------------------Authentication-------------------------------- ------------------------------------------------------------------------------ 7/27/2016 9:17 AM Client-Info Version: 0.11.4 7/27/2016 9:17 AM Client-Info OS: Windows 7/27/2016 9:17 AM Middleware::Authentication Waiting for authentication timeout to pass 7/29/2016 9:19 AM Middleware::Communication Download: http://172.16.23.1/fog/management/other/ssl/srvpublic.crt 7/29/2016 9:19 AM Data::RSA FOG Server CA cert found 7/29/2016 9:19 AM Data::RSA ERROR: Certificate validation failed 7/29/2016 9:19 AM Data::RSA ERROR: Trust chain did not complete to the known authority anchor. Errors: The signature of the certificate cannot be verified. (NotSignatureValid), A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. (NotTimeValid) 7/29/2016 9:19 AM Middleware::Authentication ERROR: Could not authenticate 7/29/2016 9:19 AM Middleware::Authentication ERROR: Certificate is not from FOG CA 7/29/2016 9:19 AM Bus Registering ParseBus in channel Power 7/29/2016 9:19 AM Middleware::Communication URL: http://172.16.23.1/fog/management/index.php?sub=requestClientInfo&mac=B8:08:CF:42:4A:FE|B8:08:CF:42:4A:FA|28:F1:0E:21:C8:0C||00:00:00:00:00:00:00:E0&newService&json 7/29/2016 9:19 AM Middleware::Authentication Waiting for authentication timeout to pass 7/29/2016 9:21 AM Middleware::Communication Download: http://172.16.23.1/fog/management/other/ssl/srvpublic.crt 7/29/2016 9:21 AM Data::RSA FOG Server CA cert found 7/29/2016 9:21 AM Data::RSA ERROR: Certificate validation failed 7/29/2016 9:21 AM Data::RSA ERROR: Trust chain did not complete to the known authority anchor. Errors: The signature of the certificate cannot be verified. (NotSignatureValid), A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. (NotTimeValid) 7/29/2016 9:21 AM Middleware::Authentication ERROR: Could not authenticate 7/29/2016 9:21 AM Middleware::Authentication ERROR: Certificate is not from FOG CA 7/29/2016 9:21 AM Middleware::Response Success 7/29/2016 9:21 AM Middleware::Communication URL: http://172.16.23.1/fog/service/getversion.php?clientver&newService&json 7/29/2016 9:21 AM Middleware::Communication URL: http://172.16.23.1/fog/service/getversion.php?newService&json 7/29/2016 9:21 AM Service Creating user agent cache 7/29/2016 9:21 AM Middleware::Response ERROR: Unable to get subsection 7/29/2016 9:21 AM Middleware::Response ERROR: Object reference not set to an instance of an object. 7/29/2016 9:21 AM Middleware::Response ERROR: Unable to get subsection 7/29/2016 9:21 AM Middleware::Response ERROR: Object reference not set to an instance of an object. 7/29/2016 9:21 AM Middleware::Response ERROR: Unable to get subsection 7/29/2016 9:21 AM Middleware::Response ERROR: Object reference not set to an instance of an object. 7/29/2016 9:21 AM Service Initializing modules ------------------------------------------------------------------------------ ---------------------------------ClientUpdater-------------------------------- ------------------------------------------------------------------------------ 7/29/2016 9:21 AM Client-Info Client Version: 0.11.4 7/29/2016 9:21 AM Client-Info Client OS: Windows 7/29/2016 9:21 AM Client-Info Server Version: 1.3.0-RC-4 7/29/2016 9:21 AM Middleware::Response Success ------------------------------------------------------------------------------ ------------------------------------------------------------------------------ ----------------------------------TaskReboot---------------------------------- ------------------------------------------------------------------------------ 7/29/2016 9:21 AM Client-Info Client Version: 0.11.4 7/29/2016 9:21 AM Client-Info Client OS: Windows 7/29/2016 9:21 AM Client-Info Server Version: 1.3.0-RC-4 7/29/2016 9:21 AM Middleware::Response ERROR: Unable to get subsection 7/29/2016 9:21 AM Middleware::Response ERROR: Object reference not set to an instance of an object. ------------------------------------------------------------------------------ --------------------------------HostnameChanger------------------------------- ------------------------------------------------------------------------------ 7/29/2016 9:21 AM Client-Info Client Version: 0.11.4 7/29/2016 9:21 AM Client-Info Client OS: Windows 7/29/2016 9:21 AM Client-Info Server Version: 1.3.0-RC-4 7/29/2016 9:21 AM Middleware::Response ERROR: Unable to get subsection 7/29/2016 9:21 AM Middleware::Response ERROR: Object reference not set to an instance of an object. ------------------------------------------------------------------------------ ---------------------------------SnapinClient--------------------------------- ------------------------------------------------------------------------------ 7/29/2016 9:21 AM Client-Info Client Version: 0.11.4 7/29/2016 9:21 AM Client-Info Client OS: Windows 7/29/2016 9:21 AM Client-Info Server Version: 1.3.0-RC-4 7/29/2016 9:21 AM Middleware::Response ERROR: Unable to get subsection 7/29/2016 9:21 AM Middleware::Response ERROR: Object reference not set to an instance of an object. ------------------------------------------------------------------------------ --------------------------------PrinterManager-------------------------------- ------------------------------------------------------------------------------ 7/29/2016 9:21 AM Client-Info Client Version: 0.11.4 7/29/2016 9:21 AM Client-Info Client OS: Windows 7/29/2016 9:21 AM Client-Info Server Version: 1.3.0-RC-4 7/29/2016 9:21 AM Middleware::Response ERROR: Unable to get subsection 7/29/2016 9:21 AM Middleware::Response ERROR: Object reference not set to an instance of an object. ------------------------------------------------------------------------------ --------------------------------PowerManagement------------------------------- ------------------------------------------------------------------------------ 7/29/2016 9:21 AM Client-Info Client Version: 0.11.4 7/29/2016 9:21 AM Client-Info Client OS: Windows 7/29/2016 9:21 AM Client-Info Server Version: 1.3.0-RC-4 7/29/2016 9:21 AM Middleware::Response ERROR: Unable to get subsection 7/29/2016 9:21 AM Middleware::Response ERROR: Object reference not set to an instance of an object. ------------------------------------------------------------------------------ ----------------------------------UserTracker--------------------------------- ------------------------------------------------------------------------------ 7/29/2016 9:25 AM Client-Info Client Version: 0.11.4 7/29/2016 9:25 AM Client-Info Client OS: Windows 7/29/2016 9:25 AM Client-Info Server Version: 1.3.0-RC-4 7/29/2016 9:25 AM Middleware::Response ERROR: Unable to get subsection 7/29/2016 9:25 AM Middleware::Response ERROR: Object reference not set to an instance of an object. 7/29/2016 9:25 AM Middleware::Communication URL: http://172.16.23.1/fog/management/index.php?sub=requestClientInfo&configure&newService&json 7/29/2016 9:25 AM Middleware::Response Success 7/29/2016 9:25 AM Service Sleeping for 132 seconds 7/29/2016 9:28 AM Middleware::Communication URL: http://172.16.23.1/fog/management/index.php?sub=requestClientInfo&mac=B8:08:CF:42:4A:FE|B8:08:CF:42:4A:FA|28:F1:0E:21:C8:0C||00:00:00:00:00:00:00:E0&newService&json 7/29/2016 9:28 AM Middleware::Authentication Waiting for authentication timeout to pass 7/29/2016 9:28 AM Middleware::Communication Download: http://172.16.23.1/fog/management/other/ssl/srvpublic.crt 7/29/2016 9:28 AM Data::RSA FOG Server CA cert found 7/29/2016 9:28 AM Data::RSA ERROR: Certificate validation failed 7/29/2016 9:28 AM Data::RSA ERROR: Trust chain did not complete to the known authority anchor. Errors: The signature of the certificate cannot be verified. (NotSignatureValid), A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. (NotTimeValid) 7/29/2016 9:28 AM Middleware::Authentication ERROR: Could not authenticate 7/29/2016 9:28 AM Middleware::Authentication ERROR: Certificate is not from FOG CA 7/29/2016 9:28 AM Middleware::Response Success 7/29/2016 9:28 AM Middleware::Communication URL: http://172.16.23.1/fog/service/getversion.php?clientver&newService&json 7/29/2016 9:28 AM Middleware::Communication URL: http://172.16.23.1/fog/service/getversion.php?newService&json 7/29/2016 9:28 AM Service Creating user agent cache 7/29/2016 9:28 AM Middleware::Response ERROR: Unable to get subsection 7/29/2016 9:28 AM Middleware::Response ERROR: Object reference not set to an instance of an object. 7/29/2016 9:28 AM Middleware::Response ERROR: Unable to get subsection 7/29/2016 9:28 AM Middleware::Response ERROR: Object reference not set to an instance of an object. 7/29/2016 9:28 AM Middleware::Response ERROR: Unable to get subsection 7/29/2016 9:28 AM Middleware::Response ERROR: Object reference not set to an instance of an object.
-
7/29/2016 9:19 AM Data::RSA ERROR: Certificate validation failed
7/29/2016 9:19 AM Data::RSA ERROR: Trust chain did not complete to the known authority anchor. Errors: The signature of the certificate cannot be verified. (NotSignatureValid), A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. (NotTimeValid)
7/29/2016 9:19 AM Middleware::Authentication ERROR: Could not authenticate
7/29/2016 9:19 AM Middleware::Authentication ERROR: Certificate is not from FOG CAWell there’s your problem. At some point you regenerated your FOG server root CA certificates, or setup a new server and didn’t transfer your keys.
-
@Joe-Schmitt Thanks Joe. I definitely did not intentionally regenerate CA cert during install. Any tips for transferring the old keys or resolving the client error with the new keys?
-
@Tom-Elliott I will say that this issue appears generally after reverting from a newer versionI believe. I’ve had to do the group reset encryption.
-
@Hanz this is unrelated now. The root CA keys are now incorrect.
-
@JoeG The best I can tell you, for now.
If you simply built a brand new server, and still have the old server available, you can do the “fixing” rather easily. If this is the case, you need to copy the ssl folder from the old in the new server’s ssl location (default is typically /opt/fog/snapins/ssl). Then you would need to rerun the FOG Installer on the new server. This will remake the public key so it matches the key pairing information from the original server, thus allowing your clients to operate.
If the above is NOT the case, and this happened to occur on the SAME server you’ve always had, it’s not going to be a fun time. The quickest way to ensure things are good immediately, and for the future would be to rebuild the “master” image removing the FOG Client, and reinstalling it. Then you would capture that image and deploy it to the hosts that require it.
I hope this helps lead you in the right direction.
-
@Tom-Elliott said in "Unable to get subsection" error with RC-4:
If you simply built a brand new server, and still have the old server available, you can do the “fixing” rather easily. If this is the case, you need to copy the ssl folder from the old in the new server’s ssl location (default is typically /opt/fog/snapins/ssl). Then you would need to rerun the FOG Installer on the new server. This will remake the public key so it matches the key pairing information from the original server, thus allowing your clients to operate.
Thanks, Tom. I have dev and prod FOG servers and luckily this error has been on my dev server. My prod server is still RC-3, I will try copying that server’s ssl directory to the dev RC-4 server.
-
@JoeG after copying over that directory you will also need to issue an SSL regen command from the fog installer. @Tom-Elliott or @Wayne-Workman can tell you how.
-
@Joe-Schmitt We wouldn’t. The public keys are automatically generated every reinstall.
-
My mistake. @JoeG what you are doing right now is cloning the identity of your prod server to your dev server. When a client installs it locks itself to a single server identity. By cloning it to multiple servers, the client will accept commands from either one.
-
I was able to copy
opt/fog/snapins/ssl/
from prod to dev server and the CA errors resolved. I get the “snapin hash does not exist error” now, but in the past recreating the snapins has resolved this for me.I will do that again and post another update. Latest logs are below in case you all have other insights. Thanks!Joe
UPDATE: Recreating snapins resolved the hash error. @Wayne-Workman mark it solved! Thank you all for your help!
------------------------------------------------------------------------------ --------------------------------Authentication-------------------------------- ------------------------------------------------------------------------------ 8/1/2016 2:38 PM Client-Info Version: 0.11.4 8/1/2016 2:38 PM Client-Info OS: Windows 8/1/2016 2:38 PM Middleware::Authentication Waiting for authentication timeout to pass 8/1/2016 2:38 PM Middleware::Communication Download: http://172.16.23.1/fog/management/other/ssl/srvpublic.crt 8/1/2016 2:38 PM Data::RSA FOG Server CA cert found 8/1/2016 2:38 PM Middleware::Authentication Cert OK 8/1/2016 2:38 PM Middleware::Communication POST URL: http://172.16.23.1/fog/management/index.php?sub=requestClientInfo&authorize&newService 8/1/2016 2:38 PM Middleware::Response Success 8/1/2016 2:38 PM Middleware::Authentication Authenticated 8/1/2016 2:38 PM Bus Registering ParseBus in channel Power 8/1/2016 2:38 PM Middleware::Communication URL: http://172.16.23.1/fog/management/index.php?sub=requestClientInfo&mac=B8:08:CF:39:02:5C|B8:08:CF:39:02:58|28:F1:0E:22:D0:9A||00:00:00:00:00:00:00:E0&newService&json 8/1/2016 2:39 PM Middleware::Response Success 8/1/2016 2:39 PM Middleware::Communication URL: http://172.16.23.1/fog/service/getversion.php?clientver&newService&json 8/1/2016 2:39 PM Middleware::Communication URL: http://172.16.23.1/fog/service/getversion.php?newService&json 8/1/2016 2:39 PM Service Creating user agent cache 8/1/2016 2:39 PM Middleware::Response Invalid time 8/1/2016 2:39 PM Middleware::Response No Printers 8/1/2016 2:39 PM Middleware::Response Module is disabled globally on the FOG server 8/1/2016 2:39 PM Service Initializing modules ------------------------------------------------------------------------------ ---------------------------------ClientUpdater-------------------------------- ------------------------------------------------------------------------------ 8/1/2016 2:39 PM Client-Info Client Version: 0.11.4 8/1/2016 2:39 PM Client-Info Client OS: Windows 8/1/2016 2:39 PM Client-Info Server Version: 1.3.0-RC-5 8/1/2016 2:39 PM Middleware::Response Success ------------------------------------------------------------------------------ ------------------------------------------------------------------------------ ----------------------------------TaskReboot---------------------------------- ------------------------------------------------------------------------------ 8/1/2016 2:39 PM Client-Info Client Version: 0.11.4 8/1/2016 2:39 PM Client-Info Client OS: Windows 8/1/2016 2:39 PM Client-Info Server Version: 1.3.0-RC-5 8/1/2016 2:39 PM Middleware::Response Success ------------------------------------------------------------------------------ ------------------------------------------------------------------------------ --------------------------------HostnameChanger------------------------------- ------------------------------------------------------------------------------ 8/1/2016 2:39 PM Client-Info Client Version: 0.11.4 8/1/2016 2:39 PM Client-Info Client OS: Windows 8/1/2016 2:39 PM Client-Info Server Version: 1.3.0-RC-5 8/1/2016 2:39 PM Middleware::Response Success 8/1/2016 2:39 PM HostnameChanger Users still logged in and enforce is disabled, delaying any further actions ------------------------------------------------------------------------------ ------------------------------------------------------------------------------ ---------------------------------SnapinClient--------------------------------- ------------------------------------------------------------------------------ 8/1/2016 2:39 PM Client-Info Client Version: 0.11.4 8/1/2016 2:39 PM Client-Info Client OS: Windows 8/1/2016 2:39 PM Client-Info Server Version: 1.3.0-RC-5 8/1/2016 2:39 PM Middleware::Response Success 8/1/2016 2:39 PM SnapinClient Snapin Found: 8/1/2016 2:39 PM SnapinClient ID: -1 8/1/2016 2:39 PM SnapinClient Name: 8/1/2016 2:39 PM SnapinClient Created: -1 8/1/2016 2:39 PM SnapinClient Action: 8/1/2016 2:39 PM SnapinClient Pack: False 8/1/2016 2:39 PM SnapinClient Hide: False 8/1/2016 2:39 PM SnapinClient Server: 8/1/2016 2:39 PM SnapinClient TimeOut: -1 8/1/2016 2:39 PM SnapinClient RunWith: 8/1/2016 2:39 PM SnapinClient RunWithArgs: 8/1/2016 2:39 PM SnapinClient Args: 8/1/2016 2:39 PM SnapinClient File: 8/1/2016 2:39 PM SnapinClient ERROR: Snapin hash does not exist ------------------------------------------------------------------------------ ------------------------------------------------------------------------------ --------------------------------PrinterManager-------------------------------- ------------------------------------------------------------------------------ 8/1/2016 2:39 PM Client-Info Client Version: 0.11.4 8/1/2016 2:39 PM Client-Info Client OS: Windows 8/1/2016 2:39 PM Client-Info Server Version: 1.3.0-RC-5 8/1/2016 2:39 PM Middleware::Response No Printers 8/1/2016 2:39 PM PrinterManager Getting installed printers ------------------------------------------------------------------------------ ------------------------------------------------------------------------------ --------------------------------PowerManagement------------------------------- ------------------------------------------------------------------------------ 8/1/2016 2:39 PM Client-Info Client Version: 0.11.4 8/1/2016 2:39 PM Client-Info Client OS: Windows 8/1/2016 2:39 PM Client-Info Server Version: 1.3.0-RC-5 8/1/2016 2:39 PM Middleware::Response Success 8/1/2016 2:39 PM PowerManagement Calculating tasks to unschedule 8/1/2016 2:39 PM PowerManagement Calculating tasks to schedule ------------------------------------------------------------------------------
-
For future readers, the steps in the wiki for moving the ssl stuff for a “new” server would also work for making “another” server have matching certs. Here is the link:
https://wiki.fogproject.org/wiki/index.php?title=FOG_Client#Maintain_Control_Of_Hosts_When_Building_New_Server