Workaround for file descriptor leak in the SSLV 4.5.15.1
search cancel

Workaround for file descriptor leak in the SSLV 4.5.15.1

book

Article ID: 438841

calendar_today

Updated On:

Products

SV3800

Issue/Introduction

SSLv may become unresponsive via GUI, reachable via SSH but unresponsive for CLD commands.  Decrypting services may also be impacted.

Attempted "restart-ui" from CLI, may not resolve unresponsive GUI.

Required reboot to decrypt correct traffic.  

 

 

Environment

SV3800B-20 deployed in network running version 4.5.15.1.

Cause

With MaxConcurrentLogins limit of 1, we have reproduced the issue with a script which continuously logs into SSLV using remote API & gets time.  Running this script from two different clients causes previous session to be killed.

sslpilot has limit of 1024 open file descriptors.

Issue seems to be rising from how user session is terminated in the underlying COE (Common Operating Environment).

Resolution

Increase MaxConcurrentLogins to 3.

A fix for this should be provided in the next GA version of SSL Visibility software.

Additional Information

Will likely see the following messages within the user_syslog_unfiltered.log:

Apr 26 21:16:58 SSLV_appliance sslpilot[16670]:  [E] Interface subsystem returned errno: 24
Apr 26 21:16:58 SSLV_appliance sslpilot[16670]:  [E] Interface subsystem return code: 10
Apr 26 21:16:58 SSLV_appliance SSLV_appliance WARN EventLog.confd- AuditNotification[logno=153, user=admin, usid=xxxxxx, msg="terminated session (reason: normal)"]
Apr 26 21:17:01 SSLV_appliance sslpilot[16670]:  [E] ALERT: No NMSB devices attached: 0
Apr 26 21:17:01 SSLV_appliance sslpilot[16670]:  [W] Interface subsystem status: ON->ERROR(0x0000008c84830010)