Usage Metering Collector cannot recognize a web proxy CA certificate

Last Updated : Nov 10, 2020 |
Prolog information

Condition

Usage Metering Collector cannot recognize a web proxy CA certificate.

Cause

Your IT infrastructure uses a web proxy to identity a man-in-the-middle attack, but the web proxy CA certificate is not added to the list of CA certificates that are trusted by curl and yum.
Use this procedure to add a CA certificate of a web proxy server to the list of CA certificates that are trusted by curl and yum.
A web proxy server inspects the HTTPS traffic between the Usage Metering server and other servers by performing a man-in-the-middle attack.
Note:
Use this procedure while installing the Usage Metering Collector for the first time.
Before you begin with the procedure, ensure that you get the web proxy's Root CA certificate in PEM certificate format from the CA. The PEM certificate format starts with "-----BEGIN CERTIFICATE-----" and ends with "-----END CERTIFICATE----".

Solution

  1. Open an SSH session to the CentOS or RHEL server on which Usage Metering Collector is installed.
    ADDITIONAL INFORMATION:
    You can use an application such as PuTTY.
    If you have manually uploaded the web proxy's Root CA certificate file to the Usage Metering Collector by using a Secure Copy (SCP) command, go to Step 3.
  2. Run the following command to add the web proxy's Root CA certificate file to the server:
    ADDITIONAL INFORMATION:
    echo | openssl s_client -showcerts -servername yum.avaya.com -connect yum.avaya.com:443 > <filename>.pem
  3. Run the following commands to install the certificate:
    ADDITIONAL INFORMATION:
    sudo yum -y install ca-certificates
    sudo cp <filename>.pem /etc/pki/ca-trust/source/anchors/
    sudo update-ca-trust
  4. If the following error message is displayed, re-run the commands shown in Step 3 to install the certificate:
    ADDITIONAL INFORMATION:
    verify error:num=20:unable to get local issuer certificate
  5. Install the web proxy's Root CA certificate for outbound connections.
    ADDITIONAL INFORMATION:
    For more information, see Installing an outbound certificate.
    This allows Usage Metering to communicate with the cloud services.