I am trying to get an endpoint enrolled on my ziti network. Here are the steps taken -
1.Installed ziti-edge-tunnel from OpenZitiโs RPM repo
2. Confirmed that systemd-resolved is working
3. Enrolled the endpoint ( got success )
4. Started ziti-edge-tunnel service
Aug 31 23:24:53 ip-10-10-10-10.us-west-2.compute.internal ziti-edge-tunnel[3447]: [ 627.424] ERROR ziti-sdk:channel.c:875 on_channel_connect_internal() ch[0] failed to connect [-3008/unknown node or service]
Also see following error -
Aug 31 23:34:53 ip-10-10-10-10.us-west-2.compute.internal ziti-edge-tunnel[3447]: [ 732.424] WARN ziti-sdk:connect.c:344 connect_timeout() conn[0.0/Connecting] connect timeout: no suitable edge router
Identities
~ > ziti edge list identities
โญโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโฌโโโโโโโโโโโโโฎ
โ ID โ NAME โ TYPE โ ATTRIBUTES โ
โโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโผโโโโโโโโโโโโโค
โ AAAAAAAA โ er1 โ Router โ all-routersโ
โ BBBBBBBB โ ep1 โ Device โ all-eps โ
โ CCCCCCCC โ ep2 โ Device โ all-eps โ
โฐโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโดโโโโโโโโโโโโโฏ
Routers
~ > ziti edge list edge-routers
โญโโโโโโโโโโโโฌโโโโโโโฌโโโโโโโโโฌโโโโโโโโโโโโโโโโฌโโโโโโโฌโโโโโโโโโโโโโฎ
โ ID โ NAME โ ONLINE โ ALLOW TRANSIT โ COST โ ATTRIBUTES โ
โโโโโโโโโโโโโผโโโโโโโผโโโโโโโโโผโโโโโโโโโโโโโโโโผโโโโโโโผโโโโโโโโโโโโโค
โ AAAAAAAA โ er1 โ true โ true โ 0 โ all-routersโ
โฐโโโโโโโโโโโโดโโโโโโโดโโโโโโโโโดโโโโโโโโโโโโโโโโดโโโโโโโดโโโโโโโโโโโโโฏ
edge-router-policies
~ > ziti edge list edge-router-policies
โญโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโฎ
โ ID โ NAME โ EDGE ROUTER ROLES โ IDENTITY ROLES โ
โโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโค
โ xxxxxxxxxxxxxxxxxxxxxx โ erp-default-allow โ #all-routers โ #all-eps โ
โ AAAAAAAAA โ edge-router-AAAAAAAA-system โ @er1 โ @er1 โ
โฐโโโโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโฏ
Went through troubleshooting steps and made sure there is no PKI setup issue. ( er.cert is the edge-router identity cert and identity.ca obtained from tunneler host enrollment )
> verifyCertAgainstPool ./er.cert ./identity.ca
Verifying that this certificate:
- ./er.cert
is valid for this ca pool:
- ./identity.ca
./er.cert: OK
============ SUCCESS! ============
What am I missing?
TIA.