Error: [TLS-Probe] Failed to create TLS connection: failed to perform TLS handshake: tls: failed to verify certificate: x509: certificate signed by unknown authority for the harbor health status
book
Article ID: 398375
calendar_today
Updated On:
Products
VMware Telco Cloud Automation
Issue/Introduction
After Renewing the Harbor certs, Below error is seen in the connected endpoints status:
message: >-
failed to create TLS connection: failed to perform TLS handshake: tls:
failed to verify certificate: x509: certificate signed by unknown
authority
severity: Error
lastSetTime: 'XXXX-XX-20T14:04:14Z'
lastTransitionTime: 'XXXX-XX-19T10:09:14Z'
- type: HarborProbeOk
reason: LoginFailed
status: 'False'
message: >-
failed to check Harbor credentials: failed to call the Harbor users
Environment
3.2
Cause
Harbor CA signed certs were not being updated in the partner system after the cert renewal.
Resolution
To have the updated certs synch in the TCA, You need to provide the certs in the TCA partner system.
Follow the below steps:
Login to TCA Manager UI
Go to partner system> Harbor> Provide the certs and the credentials and save the changes.
In the partner system, verify that the Harbor is in enabled state after the changes
Check the connected endpoints status now . The error should have been gone now. Note: It will take few minutes(approx 5-10min ) to show the updated status
In case , the error is still seen in the connected endpoints status, then edit and Update the harbor addon and save the changes to provision it again to take effect.
Additional Information
The capability of specifying a certificate for harbor was added in TCA 3.1 If the harbor is registered in partner system, you should update the certificate in partner system (which updates harbor addon automatically)