Problems with check_nrpe+SSL, and I have read the FAQ

Ludwig Pummer Ludwig.Pummer at Copart.Com
Mon Oct 17 18:09:09 CEST 2005


> -----Original Message-----
> From: nagios-users-admin at lists.sourceforge.net 
> [mailto:nagios-users-admin at lists.sourceforge.net] On Behalf 
> Of Eivind Olsen
> Sent: Monday, October 17, 2005 5:14 AM
> To: nagios-users at lists.sourceforge.net
> Subject: [Nagios-users] Problems with check_nrpe+SSL, and I 
> have read the FAQ
> 
> Hello.
> 
> I'm trying to set up check_nrpe 2.0 to use SSL, but I can't 
> get it to work. The nagios-server (192.168.1.4) is running 
> Solaris 10, the other machine 192.168.1.2 is running Solaris 
> 8. The nrpe-daemon is run from the command line in 
> daemon-mode (-d option), not from inetd.
> I'm currently doing all testing from the command line. Here's 
> what I do on the nagios-server:

I haven't had to try to make it work in Solaris 8, so I'm afraid I can't
help you there. However, I can tell you that I wasn't able to get the
OpenSSL that ships with Solaris 10 to work with NRPE.

On the Solaris 10 box, run the nrpe daemon and try to check_nrpe on
localhost. Don't forget to add localhost to the allowed_hosts line. If
you get the "Could not complete SSL handshake" there too, you're running
into the same issue I had.

I compiled OpenSSL from the source package and linked nrpe against it
(./configure --with-ssl-lib=/usr/local/openssl/lib
--with-ssl-inc=/usr/local/openssl" and then it worked. One of the
OpenSSL packages on one of the free package sites like sunfreeware.com
would probably work for you.

--Ludwig Pummer


-------------------------------------------------------
This SF.Net email is sponsored by:
Power Architecture Resource Center: Free content, downloads, discussions,
and more. http://solutions.newsforge.com/ibmarch.tmpl
_______________________________________________
Nagios-users mailing list
Nagios-users at lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nagios-users
::: Please include Nagios version, plugin version (-v) and OS when reporting any issue. 
::: Messages without supporting info will risk being sent to /dev/null





More information about the Users mailing list