Help Center/ MapReduce Service/ User Guide/ MRS Cluster O&M/ MRS Cluster Alarm Handling Reference/ ALM-24015 Flume MonitorServer Certificate File Has Expired
Updated on 2024-09-23 GMT+08:00

ALM-24015 Flume MonitorServer Certificate File Has Expired

This section applies to MRS 3.2.0 or later.

Alarm Description

MonitorServer checks whether its certificate file in the system has expired every hour. This alarm is generated when the server certificate has expired. This alarm is automatically cleared when the MonitorServer certificate file becomes valid again.

Alarm Attributes

Alarm ID

Alarm Severity

Auto Cleared

24015

Major

Yes

Alarm Parameters

Parameter

Description

Source

Specifies the cluster for which the alarm was generated.

ServiceName

Specifies the service for which the alarm was generated.

RoleName

Specifies the role for which the alarm was generated.

HostName

Specifies the host for which the alarm was generated.

Impact on the System

The Flume client cannot access the Flume server.

Possible Causes

The MonitorServer certificate file has expired.

Handling Procedure

View alarm information.

  1. Log in to FusionInsight Manager and choose O&M. In the navigation pane on the left, choose Alarm > Alarms. On the page that is displayed, locate the row containing ALM-24015 MonitorServer Certificate Has Expired, and view the Location information. View the IP address of the instance for which the alarm is generated.

Check whether the certificate file in the system is valid. If it is not, generate a new one.

  1. Log in to the node for which the alarm is generated as user root and run the su - omm command to switch to user omm.
  2. Run the following command to go to the MonitorServer certificate file directory:

    cd ${BIGDATA_HOME}/FusionInsight_Porter_*/install/FusionInsight-Flume-*/flume/conf

  3. Run the following command to check the effective time and expiration time of the user certificate to determine whether the certificate file is still in the validity period:

    openssl x509 -noout -text -in ms_sChat.crt
    • If yes, go to 9.
    • If no, go to 5.

  4. Run the following command to go to the Flume script directory:

    cd ${BIGDATA_HOME}/FusionInsight_Porter_*/install/FusionInsight-Flume-*/flume/bin

  5. Run the following command to generate a new certificate file. Then, check whether the alarm is automatically cleared one hour later.

    sh geneJKS.sh -m Custom password of the MonitorServer certificate on the server -n Custom password of the MonitorServer certificate on the client
    • If yes, go to 8.
    • If no, go to 7.
      The custom certificate passwords must meet the following complexity requirements:
      • Contain at least four types of uppercase letters, lowercase letters, digits, and special characters.
      • Contain 8 to 64 characters.
      • Be changed periodically (for example, every three months), and certificates and trust lists are generated again to ensure security.

  6. Log in to the Flume node for which the alarm is generated as user omm and repeat 5 to 6. Then, check whether the alarm is automatically cleared one hour later.

    • If yes, go to 8.
    • If no, go to 9.

  7. Check whether this alarm is generated again during periodic system check.

    • If yes, go to 9.
    • If no, no further action is required.

Collect fault information.

  1. On FusionInsight Manager, choose O&M. In the navigation pane on the left, choose Log > Download.
  2. Select MonitorServer in the required cluster for Service.
  3. Click the edit icon in the upper right corner, and set Start Date and End Date for log collection to 10 minutes ahead of and after the alarm generation time, respectively. Then, click Download.
  4. Contact O&M personnel and provide the collected logs.

Alarm Clearance

This alarm is automatically cleared after the fault is rectified.

Related Information

None