<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Glad to be of help 🙂</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
For now I have manually authorized my agents.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Thanks for opening the thread</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Regards,</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Ronald</div>
<div id="appendonsend" style="color: inherit;"></div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<hr style="display: inline-block; width: 98%;">
<div id="divRplyFwdMsg" dir="ltr" style="color: inherit;"><span style="font-family: Calibri, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><b>From:</b> Slawek Figiel <slawek@isc.org><br>
<b>Sent:</b> Tuesday, August 27, 2024 18:21<br>
<b>To:</b> DDFR | Ronald Blaas <ronald.blaas@ddfr.nl>; stork-users@lists.isc.org <stork-users@lists.isc.org><br>
<b>Subject:</b> Re: [stork-users] problems re-registering agent</span>
<div> </div>
</div>
<div style="font-size: 11pt;">Ronald,<br>
<br>
I analyzed your problem, and it seems to be a bug in the Stork agent<br>
that we introduced, together with the improvements to the registration<br>
process in recent releases.<br>
<br>
Previously, you could start the Stork agent and then perform the<br>
registration using the server token. In that case, the Stork agent<br>
process had been responding correctly to the ping request.<br>
<br>
Now, you cannot run the Stork agent without GRPC credentials. So, no<br>
process would listen to the ping request, and the ping fails.<br>
<br>
The good news is the registration artifacts are created before the ping<br>
check. So, you can use your Stork agent installation even if the ping<br>
returns an error.<br>
<br>
I opened <a href="https://gitlab.isc.org/isc-projects/stork/-/issues/1491" id="OWAaaf30ad1-d995-bedf-2081-890006aac020" class="OWAAutoLink" data-auth="NotApplicable">
https://eur05.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgitlab.isc.org%2Fisc-projects%2Fstork%2F-%2Fissues%2F1491&data=05%7C02%7Cronald.blaas%40ddfr.nl%7Cdfc0ae462e344f97ff7908dcc6b4641c%7C61b60fb772d74ba78225d9b5369d780a%7C0%7C0%7C638603725334790649%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=cqcg7lq2MZErMi9CVhwaR94qyPV5N5bWMcYDJ6d3zyo%3D&reserved=0</a> to<br>
solve the problem.<br>
<br>
Regards,<br>
Slawek Figiel<br>
<br>
On 27/08/2024 16:05, DDFR | Ronald Blaas wrote:<br>
> Hi Slawek,<br>
><br>
> Did find this in the syslog from the stork server:<br>
> Aug 27 16:02:24 stork-test stork-server[1011]: time="2024-08-27<br>
> 16:02:24" level="error" msg="failed to ping the Stork agent<br>
> host.domain.xx:8080: grpc manager is unable to re-establish connection<br>
> with the agent host.domain.xx:8080: rpc error: code = Unavailable desc =<br>
> connection error: desc = \"transport: Error while dialing: dial tcp<br>
> xx.xx.xx.xx:8080: connect: connection refused\"" file=" <br>
> machines.go:569 "<br>
><br>
><br>
> Regards,<br>
><br>
> Ronald<br>
><br>
> ------------------------------------------------------------------------<br>
> *From:* Stork-users <stork-users-bounces@lists.isc.org> on behalf of<br>
> DDFR | Ronald Blaas <ronald.blaas@ddfr.nl><br>
> *Sent:* Tuesday, August 27, 2024 15:24<br>
> *To:* Slawek Figiel <slawek@isc.org>; stork-users@lists.isc.org<br>
> <stork-users@lists.isc.org><br>
> *Subject:* Re: [stork-users] problems re-registering agent<br>
> Here is sone info:<br>
><br>
> stork-agent register<br>
> >>> Enter the URL of the Stork server: <a href="https://xxxxx8080" id="OWAec9fc1ba-5b3d-fdf0-26e5-bef1f0c6156f" class="OWAAutoLink" data-auth="NotApplicable">
https://xxxxx8080</a><br>
> >>> Enter the Stork server access token (optional):<br>
> >>> Enter IP address or FQDN of the host with Stork agent (for the<br>
> Stork server connection) [xxxxxxx]:<br>
> >>> Enter port number that Stork Agent will listen on [8080]:<br>
> INFO[2024-08-27 15:01:14] register.go:34 Forced agent<br>
> certificates regeneration.<br>
> INFO[2024-08-27 15:01:14] register.go:342 <br>
> =============================================================================<br>
> INFO[2024-08-27 15:01:14] register.go:343 AGENT TOKEN:<br>
> 7A25420D275543E91CEB4B645DED30E6DDAD2C3F8C485E1C156239DBF856F98E<br>
> INFO[2024-08-27 15:01:14] register.go:344 <br>
> =============================================================================<br>
> INFO[2024-08-27 15:01:14] register.go:349 Machine will be<br>
> automatically registered using the server token<br>
> INFO[2024-08-27 15:01:14] register.go:350 Agent token is<br>
> printed above for informational purposes only<br>
> INFO[2024-08-27 15:01:14] register.go:351 User does not need<br>
> to copy or verify the agent token during registration via the server token<br>
> INFO[2024-08-27 15:01:14] register.go:352 It will be sent to<br>
> the server but it is not directly used in this type of machine registration<br>
> INFO[2024-08-27 15:01:14] register.go:361 Try to register<br>
> agent in Stork Server<br>
> INFO[2024-08-27 15:01:14] register.go:212 Machine registered<br>
> INFO[2024-08-27 15:01:14] register.go:233 Stored agent-signed<br>
> cert and CA cert<br>
> ERRO[2024-08-27 15:01:14] register.go:390 Retrying ping 1/3<br>
> due to error error="problem pinging machine: Cannot ping<br>
> machine"<br>
> ERRO[2024-08-27 15:01:16] register.go:390 Retrying ping 2/3<br>
> due to error error="problem pinging machine: Cannot ping<br>
> machine"<br>
> ERRO[2024-08-27 15:01:20] register.go:395 Cannot ping machine<br>
> error="problem pinging machine: Cannot ping<br>
> machine"<br>
> FATA[2024-08-27 15:01:20] main.go:321 Registration failed<br>
><br>
><br>
> In stork I do see the agent appearing.. (but not communicating)<br>
><br>
> Syslog not showing anything helpfull<br>
><br>
> If needed I can test just about anything (as this is a test setup)<br>
><br>
> Regards,<br>
><br>
> Ronald<br>
><br>
> ------------------------------------------------------------------------<br>
> *From:* Stork-users <stork-users-bounces@lists.isc.org> on behalf of<br>
> DDFR | Ronald Blaas <ronald.blaas@ddfr.nl><br>
> *Sent:* Tuesday, August 27, 2024 14:42<br>
> *To:* Slawek Figiel <slawek@isc.org>; stork-users@lists.isc.org<br>
> <stork-users@lists.isc.org><br>
> *Subject:* Re: [stork-users] problems re-registering agent<br>
> I can however reproduce the problem on a test system.<br>
><br>
> Any particular logging your after ?<br>
><br>
> Regards,<br>
> Ronald<br>
><br>
> Met vriendelijke groet,<br>
><br>
><br>
> Ronald Blaas<br>
><br>
><br>
><br>
> ------------------------------------------------------------------------<br>
> *From:* Stork-users <stork-users-bounces@lists.isc.org> on behalf of<br>
> DDFR | Ronald Blaas <ronald.blaas@ddfr.nl><br>
> *Sent:* Tuesday, August 27, 2024 12:24<br>
> *To:* Slawek Figiel <slawek@isc.org>; stork-users@lists.isc.org<br>
> <stork-users@lists.isc.org><br>
> *Subject:* Re: [stork-users] problems re-registering agent<br>
> Hi Slawek,<br>
><br>
> Unfortunately, I cannot.<br>
><br>
> I do not see the same errors in the syslog.<br>
><br>
> I only saw the error while running stork-agent register<br>
><br>
><br>
> Is there a way I can check the server token?<br>
><br>
> Maybe the token has changed (or I just made a typo)<br>
><br>
> NOTE: when entering the token whilst registering the input is not shown.<br>
> This is expected behavior ?<br>
><br>
><br>
><br>
> Also good to note. When I upgraded my second dhcp server it did connect<br>
> automatically but I had to authenticate the client again.<br>
><br>
> This was unexpected as I have the server token configured in the agent.env<br>
><br>
><br>
> Regards,<br>
><br>
><br>
> Ronald<br>
><br>
><br>
><br>
> ------------------------------------------------------------------------<br>
> *From:* Stork-users <stork-users-bounces@lists.isc.org> on behalf of<br>
> Slawek Figiel <slawek@isc.org><br>
> *Sent:* Tuesday, August 27, 2024 12:14<br>
> *To:* stork-users@lists.isc.org <stork-users@lists.isc.org><br>
> *Subject:* Re: [stork-users] problems re-registering agent<br>
> Hello Roland!<br>
><br>
> I'm glad to hear your original problem has been solved.<br>
><br>
> Could you provide some logs generated when you try registering the<br>
> machine using the server token?<br>
><br>
> Regards,<br>
> Slawek Figiel<br>
><br>
> On 27/08/2024 12:02, DDFR | Ronald Blaas wrote:<br>
> > And just to be complete<br>
> ><br>
> > I am registering with a server token.<br>
> ><br>
> ><br>
> > I have now tried registering the agent without a token which is working<br>
> > just fine (after authorizing the agent in stork server)<br>
> ><br>
> > Still wondering why the server token option is not working / ping not<br>
> > working<br>
> ><br>
> > Regards,<br>
> ><br>
> > Ronald<br>
> ><br>
> > ------------------------------------------------------------------------<br>
> > *From:* Stork-users <stork-users-bounces@lists.isc.org> on behalf of<br>
> > DDFR | Ronald Blaas <ronald.blaas@ddfr.nl><br>
> > *Sent:* Tuesday, August 27, 2024 11:49<br>
> > *To:* Stork-users <stork-users@lists.isc.org><br>
> > *Subject:* Re: [stork-users] problems re-registering agent<br>
> > So I am now a step further.<br>
> ><br>
> > I had a mismatch in version number (server vs agent)<br>
> > Agent was upgrade to v1.18 whilst server was still on v1.15<br>
> ><br>
> > After upgrading the server I see the token being installed on the client<br>
> > but no I am facing an issue saying cannot ping machine.<br>
> ><br>
> > I can ping the server from client as well as the client from server.<br>
> > So i am a bit confused what is going wrong here.<br>
> ><br>
> > Any insights?<br>
> ><br>
> > Regards,<br>
> > ROnald<br>
> ><br>
> ><br>
> ><br>
> > ------------------------------------------------------------------------<br>
> > *From:* Stork-users <stork-users-bounces@lists.isc.org> on behalf of<br>
> > DDFR | Ronald Blaas <ronald.blaas@ddfr.nl><br>
> > *Sent:* Tuesday, August 27, 2024 10:47<br>
> > *To:* Stork-users <stork-users@lists.isc.org><br>
> > *Subject:* [stork-users] problems re-registering agent<br>
> > Hi all,<br>
> ><br>
> > Today I updated my ubuntu system and with the update kea (and stork<br>
> > agent) have been updated.<br>
> > The result is that stork is able to see the status of kea load balancing<br>
> > but is unable to communicate with the stork agent.<br>
> ><br>
> > After some investigation it appears that there is a problem with the<br>
> > certificate.<br>
> ><br>
> > I am trying to re-register the agent but running into an error:<br>
> ><br>
> > ERRO[2024-08-27 10:38:31] register.go:368 Problem registering<br>
> > machine error="missing serverCertFingerprint in<br>
> > response from server for registration request"<br>
> > FATA[2024-08-27 10:38:31] main.go:321 Registration failed<br>
> ><br>
> > Any help how to fix this?<br>
> ><br>
> > Kind regards,<br>
> ><br>
> > Ronald<br>
> ><br>
> --<br>
> Stork-users mailing list<br>
> Stork-users@lists.isc.org<br>
> <a href="https://lists.isc.org/mailman/listinfo/stork-users" id="OWA159f1800-ebca-2b8e-e60f-012435abda92" class="OWAAutoLink" data-auth="NotApplicable">
https://eur05.safelinks.protection.outlook.com/?url=https%3A%2F%2Flists.isc.org%2Fmailman%2Flistinfo%2Fstork-users&data=05%7C02%7Cronald.blaas%40ddfr.nl%7Cdfc0ae462e344f97ff7908dcc6b4641c%7C61b60fb772d74ba78225d9b5369d780a%7C0%7C0%7C638603725334800523%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=9ZW6Z8jfcptvNGCLB4wQ1nQtJxFO4zJkvHapDOU2pFc%3D&reserved=0</a> <<a href="https://lists.isc.org/mailman/listinfo/stork-users" id="OWA9b66d38a-9731-7a11-76e7-30cebd8c884c" class="OWAAutoLink" data-auth="NotApplicable">https://eur05.safelinks.protection.outlook.com/?url=https%3A%2F%2Flists.isc.org%2Fmailman%2Flistinfo%2Fstork-users&data=05%7C02%7Cronald.blaas%40ddfr.nl%7Cdfc0ae462e344f97ff7908dcc6b4641c%7C61b60fb772d74ba78225d9b5369d780a%7C0%7C0%7C638603725334808364%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=loBbVXUG5KD%2FbsNgkz0%2FCNShXxKKC1T7BTsjt9a%2F72c%3D&reserved=0</a>></div>
</body>
</html>