Error:
An unexpected error occurred. Please click Reload to try again.
Error:
An unexpected error occurred. Please click Reload to try again.
连接失败WINRM通过 https ,无法获得基本约束 - Knowledge Base - Palo Alto Networks

连接失败WINRM通过 https ,无法获得基本约束

31946
Created On 06/14/22 02:18 AM - Last Modified 03/24/23 07:29 AM


Symptom


  • WINRM服务器监控状态显示未连接。
  • 用户 ID 日志 (少 mp-log useridd.log ) 显示“无法获取基本约束”错误
Error: pan_user_id_winrm_query(pan_user_id_win.c:2762): failed to connect to winrm server Error: pan_user_id_winrm_query(pan_user_id_win.c:2806): Connection failed. response code = 0, error: SSL peer certificate or SSH remote key was not OK in vsys 1 Error: pan_user_id_winrm_verify_cert_cb(pan_user_id_win.c:2922): Unable to get basic constraints


Environment


  • 任何帕洛阿尔托firewall.
  • Windows 远程管理 (WinRM) 服务器


Cause


  • 服务器证书用于WINRM服务器缺少导致此问题的密钥扩展
  • 基本约束是服务器证书的密钥扩展。
  • '基本约束扩展标识证书的主题是否是CA以及包含此证书的有效证书路径的最大深度。


Resolution


使用基本约束密钥扩展重新配置服务器证书并将此证书绑定到WINRM服务器来解决这个问题。

Additional Information


基本约束

Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000Cq1LCAS&lang=zh_CN&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language