スキップしてコンテンツを表示

private key for MqttCertificate is not set

0

I consistently get this at greengrass startup

[2019-07-12T15:30:56.744Z][DEBUG]-[3]GK Remote: Got request: /2016-11-01/remoteCrypto/publickey/MqttCertificate
[2019-07-12T15:30:56.744Z][WARN]-[5]GK Remote: Error retrieving public key data: ErrPrincipalNotConfigured: private key for MqttCertificate is not set

Not sure if its related, but when I run the python tester, the publisher runs with no errors, looking like its publishing to the local gg broker. The subscriber runs with no errors, but never receives any messages. On top of that I get zero greengrass indicating anything about connections from those devices.

Maybe related when I try to set one of the devices to sync to the cloud that sync always fails.

I've seen at least a dozen posts about this error/warning/message. But none seem to have any resolution or insight into what the implication of this message means.

Edited by: memelet on Jul 12, 2019 9:00 AM

質問済み 6年前304ビュー
8回答
0

I've tried all manner of subscriptions:

pub -> sub
pub -> cloud
cloud -> sub
shadow -> ...

These do get reflected in the deployment group config, but seem to have no effect.

Edited by: memelet on Jul 12, 2019 9:06 AM

回答済み 6年前
0

I can however publish directly to the iot broker. It's just using the greengrass broker that does not work at all.

回答済み 6年前
0

With core logging set to DEBUG I get these when publishing to the core

==> GGConnManager.log <==
[2019-07-12T16:14:04.989Z][DEBUG]-Checking if client fingerprint is valid.	{"fingerprint": "d6cc89deb4017c1c07ab8cbf7e71aa561e62342b3ddfb7877fc7c979c43cc110", "clientId": "lm-connect_Collector1"}
[2019-07-12T16:14:04.989Z][DEBUG]-Add an incoming connection.	{"clientId": "lm-connect_Collector1", "address": "127.0.0.1:51169"}
[2019-07-12T16:14:04.989Z][DEBUG]-Added a new client connection.	{"clientId": "lm-connect_Collector1"}
[2019-07-12T16:14:04.989Z][DEBUG]-Connection refused.	{"address": "127.0.0.1:51169", "errorString": "Connection Refused: not authorized"}
[2019-07-12T16:14:04.989Z][DEBUG]-Delete a connection.	{"clientId": "lm-connect_Collector1", "address": "<nil>"}
[2019-07-12T16:14:04.99Z][DEBUG]-Deleted a client connection.	{"address": "<nil>"}
[2019-07-12T16:14:04.99Z][DEBUG]-Removing device connection.{"clientId": "lm-connect_Collector1", "address": "127.0.0.1:51169"}
[2019-07-12T16:14:04.99Z][DEBUG]-Close and clean up connection.	{"address": "<nil>"}
[2019-07-12T16:14:04.99Z][DEBUG]-Close connection	{"address": "<nil>"}
[2019-07-12T16:14:05.998Z][DEBUG]-Checking if client fingerprint is valid.	{"fingerprint": "d6cc89deb4017c1c07ab8cbf7e71aa561e62342b3ddfb7877fc7c979c43cc110", "clientId": "lm-connect_Collector1"}
[2019-07-12T16:14:05.998Z][DEBUG]-Add an incoming connection.	{"clientId": "lm-connect_Collector1", "address": "127.0.0.1:45277"}
[2019-07-12T16:14:05.999Z][DEBUG]-Added a new client connection.	{"clientId": "lm-connect_Collector1"}
[2019-07-12T16:14:05.999Z][DEBUG]-Connection refused.	{"address": "127.0.0.1:45277", "errorString": "Connection Refused: not authorized"}
[2019-07-12T16:14:05.999Z][DEBUG]-Delete a connection.	{"clientId": "lm-connect_Collector1", "address": "<nil>"}
[2019-07-12T16:14:05.999Z][DEBUG]-Deleted a client connection.	{"address": "<nil>"}
[2019-07-12T16:14:05.999Z][DEBUG]-Removing device connection.	{"clientId": "lm-connect_Collector1", "address": "127.0.0.1:45277"}
[2019-07-12T16:14:05.999Z][DEBUG]-Close and clean up connection.	{"address": "<nil>"}
[2019-07-12T16:14:05.999Z][DEBUG]-Close connection	{"address": "<nil>"}
[2019-07-12T16:14:08.01Z][DEBUG]-Checking if client fingerprint is valid.	{"fingerprint": "d6cc89deb4017c1c07ab8cbf7e71aa561e62342b3ddfb7877fc7c979c43cc110", "clientId": "lm-connect_Collector1"}
[2019-07-12T16:14:08.01Z][DEBUG]-Add an incoming connection.{"clientId": "lm-connect_Collector1", "address": "127.0.0.1:52545"}
[2019-07-12T16:14:08.01Z][DEBUG]-Added a new client connection.	{"clientId": "lm-connect_Collector1"}
[2019-07-12T16:14:08.01Z][DEBUG]-Connection refused.	{"address": "127.0.0.1:52545", "errorString": "Connection Refused: not authorized"}
[2019-07-12T16:14:08.01Z][DEBUG]-Delete a connection.	{"clientId": "lm-connect_Collector1", "address": "<nil>"}
[2019-07-12T16:14:08.01Z][DEBUG]-Deleted a client connection.	{"address": "<nil>"}
[2019-07-12T16:14:08.01Z][DEBUG]-Removing device connection.{"clientId": "lm-connect_Collector1", "address": "127.0.0.1:52545"}
[2019-07-12T16:14:08.01Z][DEBUG]-Close and clean up connection.	{"address": "<nil>"}
[2019-07-12T16:14:08.01Z][DEBUG]-Close connection	{"address": "<nil>"}
[2019-07-12T16:14:12.123Z][DEBUG]-Checking if client fingerprint is valid.	{"fingerprint": "d6cc89deb4017c1c07ab8cbf7e71aa561e62342b3ddfb7877fc7c979c43cc110", "clientId": "lm-connect_Collector1"}
[2019-07-12T16:14:12.123Z][DEBUG]-Add an incoming connection.	{"clientId": "lm-connect_Collector1", "address": "127.0.0.1:55259"}
[2019-07-12T16:14:12.123Z][DEBUG]-Added a new client connection.	{"clientId": "lm-connect_Collector1"}
[2019-07-12T16:14:12.123Z][DEBUG]-Connection refused.	{"address": "127.0.0.1:55259", "errorString": "Connection Refused: not authorized"}
[2019-07-12T16:14:12.123Z][DEBUG]-Delete a connection.	{"clientId": "lm-connect_Collector1", "address": "<nil>"}
[2019-07-12T16:14:12.123Z][DEBUG]-Deleted a client connection.	{"address": "<nil>"}
[2019-07-12T16:14:12.123Z][DEBUG]-Removing device connection.	{"clientId": "lm-connect_Collector1", "address": "127.0.0.1:55259"}
[2019-07-12T16:14:12.123Z][DEBUG]-Close and clean up connection.	{"address": "<nil>"}
[2019-07-12T16:14:12.123Z][DEBUG]-Close connection	{"address": "<nil>"}

So it appears the connection is being refused. The python tester (ie, basicDiscovery.py) output does not indicate this at all.

Why is a connection refused message at the debug level? Seems that's a pretty important message. In any case, it would be nice if the reason for the refusal was logged.

Edited by: memelet on Jul 12, 2019 9:17 AM

回答済み 6年前
0

Solved as user error: I was using the wrong certs for the publisher.

Would be really nice if the python basicDiscovery.py would emit an error when it cannot authenticate.

回答済み 6年前
0

So, it seems the original log in runtime.log -- private key for MqttCertificate is not set -- seems to be a decoy.

回答済み 6年前
0

Hi memelet,

That error is covered in the Troubleshooting guide.
https://docs.aws.amazon.com/greengrass/latest/developerguide/gg-troubleshooting.html

Thanks,
KR-AWS

AWS
回答済み 6年前
0

Hi KR-AWS ,

thanks for the link explaining the underlying issue. Something is not right here, 'Error' word means to me an issue I shall deal with, however in this case this is not actually an error, just an information. It'd be nice to have something more accurate here.

BR / blelump

回答済み 6年前
0

Hi BR, this issue is logged as a warning [WARN]-[5]GK Remote: Error retrieving public key data: ErrPrincipalNotConfigured: private key for MqttCertificate is not set. as mentioned here https://docs.aws.amazon.com/greengrass/latest/developerguide/gg-troubleshooting.html#troubleshoot-mqttcertificate-warning
Do you suggest different ways?

回答済み 6年前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

関連するコンテンツ