# Knife bootstrap issue

**URL:** <https://discourse.chef.io/t/knife-bootstrap-issue/15076>\
**Category:** Chef Infra (archive)\
**Created:** [May 7, 2019, 5:05pm UTC](https://discourse.chef.io/t/knife-bootstrap-issue/15076 "2019-05-07T17:05:36Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![thekbass](https://avatars.discourse-cdn.com/v4/letter/t/e0b2c6/32.png) [@thekbass](https://discourse.chef.io/u/thekbass)\
**Post date:** [May 7, 2019, 5:05pm UTC](https://discourse.chef.io/t/knife-bootstrap-issue/15076/1 "2019-05-07T17:05:36Z")

</div>

Hello,

I am fairly new to Chef and I am trying to bootstrap to a Linux node. I am able to run the knife bootstrap command knife bootstrap IP -x username -P password --sudo --use-sudo-password  
I am able to connect to Linux node, it performs the install then I get ERROR: SSL Validation failure connecting to host: localhost - SSL\_connect returned=1 errno=0 state=error: certificate verify failed.

However, my client.rb file has a flag ssl\_verfy\_mode :verify\_none  
In addition, I have logged into the Linux node, ran knife ssl fetch and knife ssl check obtaining the Chef Server certificate but I am still getting the SSL connection error.

Any help would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![Larryc](https://avatars.discourse-cdn.com/v4/letter/l/c6cbf5/32.png) [@Larryc](https://discourse.chef.io/u/Larryc)\
**Post date:** [May 7, 2019, 5:14pm UTC](https://discourse.chef.io/t/knife-bootstrap-issue/15076/2 "2019-05-07T17:14:02Z")

</div>

Did you try bootstrapping using the hostname instead of the IP address? While it is possible to attach an SSL certificate to an IP address I am not sure chef will function that way.

---

<div class="post-metadata">

**Author:** ![thekbass](https://avatars.discourse-cdn.com/v4/letter/t/e0b2c6/32.png) [@thekbass](https://discourse.chef.io/u/thekbass)\
**Post date:** [May 7, 2019, 5:15pm UTC](https://discourse.chef.io/t/knife-bootstrap-issue/15076/3 "2019-05-07T17:15:20Z")

</div>

I have tried both FQDN and IP but same results.

---

<div class="post-metadata">

**Author:** ![Larryc](https://avatars.discourse-cdn.com/v4/letter/l/c6cbf5/32.png) [@Larryc](https://discourse.chef.io/u/Larryc)\
**Post date:** [May 7, 2019, 5:16pm UTC](https://discourse.chef.io/t/knife-bootstrap-issue/15076/4 "2019-05-07T17:16:14Z")

</div>

Is it possible for you to prove the stacktrace and just remove any identifiable information. It would make this easier to troubleshoot.

---

<div class="post-metadata">

**Author:** ![bcorner\_fan](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/bcorner_fan/32/2237_2.png) [@bcorner\_fan](https://discourse.chef.io/u/bcorner_fan)\
**Post date:** [May 7, 2019, 5:19pm UTC](https://discourse.chef.io/t/knife-bootstrap-issue/15076/5 "2019-05-07T17:19:58Z")

</div>

Sounds like your chef server may have a self signed cert? Try adding `--node-ssl-verify-mode none` to your bootstrap command. If that doesn't fix it. Try adding `-V -V` to generate a debug output. should tell you what the SSL error is exactly.

---

<div class="post-metadata">

**Author:** ![thekbass](https://avatars.discourse-cdn.com/v4/letter/t/e0b2c6/32.png) [@thekbass](https://discourse.chef.io/u/thekbass)\
**Post date:** [May 7, 2019, 5:32pm UTC](https://discourse.chef.io/t/knife-bootstrap-issue/15076/6 "2019-05-07T17:32:27Z")

</div>

Since I added the --node-ssl-verify-mode none within the bootstrap command I now get a 401 unauthorized. Here is the stacktrace output

chef-stacktrace.out  
Generated at 2019-05-07 13:26:23 -0400  
Net::HTTPServerException: 401 "Unauthorized"  
/opt/chef/embedded/lib/ruby/2.5.0/net/http/response.rb:122:in `error!' /opt/chef/embedded/lib/ruby/gems/2.5.0/gems/chef-14.12.9/lib/chef/http.rb:152:in`request'  
/opt/chef/embedded/lib/ruby/gems/2.5.0/gems/chef-14.12.9/lib/chef/http.rb:115:in `get' /opt/chef/embedded/lib/ruby/gems/2.5.0/gems/chef-14.12.9/lib/chef/node.rb:590:in`load'  
/opt/chef/embedded/lib/ruby/gems/2.5.0/gems/chef-14.12.9/lib/chef/node.rb:574:in `find_or_create' /opt/chef/embedded/lib/ruby/gems/2.5.0/gems/chef-14.12.9/lib/chef/policy_builder/dynamic.rb:72:in`load\_node'  
/opt/chef/embedded/lib/ruby/gems/2.5.0/gems/chef-14.12.9/lib/chef/client.rb:472:in `load_node' /opt/chef/embedded/lib/ruby/gems/2.5.0/gems/chef-14.12.9/lib/chef/client.rb:267:in`run'  
/opt/chef/embedded/lib/ruby/gems/2.5.0/gems/chef-14.12.9/lib/chef/application.rb:303:in `run_with_graceful_exit_option' /opt/chef/embedded/lib/ruby/gems/2.5.0/gems/chef-14.12.9/lib/chef/application.rb:279:in`block in run\_chef\_client'  
/opt/chef/embedded/lib/ruby/gems/2.5.0/gems/chef-14.12.9/lib/chef/local\_mode.rb:44:in `with_server_connectivity' /opt/chef/embedded/lib/ruby/gems/2.5.0/gems/chef-14.12.9/lib/chef/application.rb:261:in`run\_chef\_client'  
/opt/chef/embedded/lib/ruby/gems/2.5.0/gems/chef-14.12.9/lib/chef/application/client.rb:449:in `run_application' /opt/chef/embedded/lib/ruby/gems/2.5.0/gems/chef-14.12.9/lib/chef/application.rb:66:in`run'  
/opt/chef/embedded/lib/ruby/gems/2.5.0/gems/chef-14.12.9/bin/chef-client:25:in `\<top (required)\>'

---

<div class="post-metadata">

**Author:** ![bcorner\_fan](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/bcorner_fan/32/2237_2.png) [@bcorner\_fan](https://discourse.chef.io/u/bcorner_fan)\
**Post date:** [May 7, 2019, 6:04pm UTC](https://discourse.chef.io/t/knife-bootstrap-issue/15076/7 "2019-05-07T18:04:01Z")

</div>

This would imply that the chef-validator.pem key is incorrect.  
You will also want to add `-N <nodename>`  
Have you put your `ORG-validator.pem` key and your `user.pem` key in your `~/.chef directory`

[https://docs.chef.io/chefdk\_setup.html](https://docs.chef.io/chefdk_setup.html) is a great resource.

---

<div class="post-metadata">

**Author:** ![thekbass](https://avatars.discourse-cdn.com/v4/letter/t/e0b2c6/32.png) [@thekbass](https://discourse.chef.io/u/thekbass)\
**Post date:** [May 7, 2019, 9:07pm UTC](https://discourse.chef.io/t/knife-bootstrap-issue/15076/8 "2019-05-07T21:07:56Z")

</div>

Solved, apparently, I had a bad client.pem file on the Linux node and a bad validator.pem. Cleared those from Chef Manage and regenerated the validator.pem and I was able to successfully bootstrap.

Thanks for all the help!
