I am following the Vertica 7.1 documentation Administrators Guide/Implementing Security/Client Authentication. I have followed documentation to create server certificate, private key, and root certificate. I use admin tools to distribute to each node in my 3 node cluster. My cluster is Centos 6.5 and has the VMart schema installed. After the configuration parameter EnableSSL is set, the documentation then says to restart the database. This is where I encounter problems. I am using admin tools to stop/start database. It won't start.
The Vertica.log shows the following messages that may be helpful:
2014-10-07 14:51:37.761 Init Session:0x7ff60000fc80 <LOG> @v_vmart_node0002: 00000/2705: Connection received: host=143.122.35.121 port=46468 (connCnt 1)
2014-10-07 14:51:37.761 Init Session:0x7ff60000fc80 <LOG> @v_vmart_node0002: 00000/4540: Received SSL negotiation startup packet
2014-10-07 14:51:37.761 Init Session:0x7ff60000fc80 <LOG> @v_vmart_node0002: 00000/4691: Sending SSL negotiation response 'S'
2014-10-07 14:51:37.782 Init Session:0x7ff60000fc80 <LOG> @v_vmart_node0002: 08V01/2805: Could not accept SSL connection: error:140890C7:SSL routines:SSL3_GET_CLIENT_CERTIFICATE:peer did not return a certificate
2014-10-07 14:51:37.782 Init Session:0x7ff60000fc80 <FATAL> @v_vmart_node0002: {SessionRun} 08006/4777: SSL initialization failure
LOCATION: ProcessStartupPacket, /scratch_a/release/vbuild/vertica/Session/ClientSession.cpp:3710
I then go to each node in the cluster and edit Vertica.conf to set EnableSSL=0 and I can start the instance.
I've tried this 3 times now creating new certificates each time. Any help would be appreciated.