我想在我的公司中将 Cloudify 3.1 与我的 Openstack 一起使用。
不幸的是,我遇到了 keystone 身份验证失败的问题。当我看到日志时,它说“SSL3_GET_SERVER_CERTIFICATE:证书验证失败”
我认为是 HTTPS 导致它失败。我看到下面的卷曲。
curl -i 'https://identity.example.com/v2.0/tokens' -X POST -H "Content-Type: application/json" -H "Accept: application/json" -H "User-Agent: python-novaclient" -d '{"auth": {"tenantName": "xxxx", "passwordCredentials": {"username": "xxxx", "password": "xxxxx"}}}'
HTTP/1.0 200 Connection Established
Proxy-agent: Apache
curl: (60) SSL certificate problem, verify that the CA cert is OK. Details:
error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
More details here: http://curl.haxx.se/docs/sslcerts.html
curl performs SSL certificate verification by default, using a "bundle"
of Certificate Authority (CA) public keys (CA certs). If the default
bundle file isn't adequate, you can specify an alternate file
using the --cacert option.
If this HTTPS server uses a certificate signed by a CA represented in
the bundle, the certificate verification probably failed due to a
problem with the certificate (it might be expired, or the name might
not match the domain name in the URL).
If you'd like to turn off curl's verification of the certificate, use
the -k (or --insecure) option.
如何在不使用-k
or的情况下使 curl 成功--insecure
?
或者,如果有人在安装 Cloudify 时有使用 HTTPS 的 openstack 经验?