# Percona PXC 5.6 cluster , IST fails with SSL

**URL:** <https://forums.percona.com/t/percona-pxc-5-6-cluster-ist-fails-with-ssl/5773>\
**Category:** Percona XtraDB Cluster 5.x\
**Created:** [July 28, 2017, 10:41am UTC](https://forums.percona.com/t/percona-pxc-5-6-cluster-ist-fails-with-ssl/5773 "2017-07-28T10:41:42Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![vvsaxena](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/vvsaxena/32/1179_2.png) [@vvsaxena](https://forums.percona.com/u/vvsaxena)\
**Post date:** [July 28, 2017, 10:41am UTC](https://forums.percona.com/t/percona-pxc-5-6-cluster-ist-fails-with-ssl/5773/1 "2017-07-28T10:41:42Z")

</div>

Hi ,  
i have 2 node cluster with SSL turned on , SST works fine but when i shutdown node 2 and perform 2-3 transactions on node1 , restarts node2 then it fails during IST sync. I see this error on node1 ( donor ).

Jul 28 11:40:40 vishalmysql1 mysqld: 2017-07-28 11:40:40 23619 [Note] WSREP: Running: ‘wsrep\_sst\_xtrabackup-v2 --role ‘donor’ --address ‘vishalmysql2:4444/xtrabackup\_sst//1’ --socket ‘/var/lib/mysql/mysql.sock’ --datadir ‘/var/lib/mysql/’ --defaults-file ‘/etc/my.cnf’ --defaults-group-suffix ‘’ --binlog ‘vishalmysql1’ --gtid ‘1ef1062a-6e4f-11e7-9633-661746480a72:60’ --bypass’  
Jul 28 11:40:40 vishalmysql1 mysqld: 2017-07-28 11:40:40 23619 [Note] WSREP: sst\_donor\_thread signaled with 0  
Jul 28 11:40:40 vishalmysql1 mysqld: 2017-07-28 11:40:40 23619 [Note] WSREP: IST sender using ssl  
Jul 28 11:40:40 vishalmysql1 mysqld: 2017-07-28 11:40:40 23619 [ERROR] WSREP: IST failed: IST sender, failed to connect ‘ssl://vishalmysql2:4568’: connect: Connection refused: 111 (Connection refused)  
Jul 28 11:40:40 vishalmysql1 mysqld: at galera/src/ist.cpp:Sender():668  
Jul 28 11:40:40 vishalmysql1 mysqld: 2017-07-28 11:40:40 23619 [Warning] WSREP: 1.0 (vishalmysql1): State transfer to 0.0 (vishalmysql2) failed: -111 (Connection refused)  
Jul 28 11:40:40 vishalmysql1 mysqld: 2017-07-28 11:40:40 23619 [Note] WSREP: Shifting DONOR/DESYNCED → JOINED (TO: 61)  
Jul 28 11:40:41 vishalmysql1 mysqld: WSREP\_SST: [INFO] Logging all stderr of SST/Innobackupex to syslog (2017-07-28 11:40:41)  
Jul 28 11:40:41 vishalmysql1 -wsrep-sst-donor: Streaming with xbstream  
Jul 28 11:40:41 vishalmysql1 -wsrep-sst-donor: Using socat as streamer  
Jul 28 11:40:41 vishalmysql1 -wsrep-sst-donor: Using openssl based encryption with socat: with key, crt, and ca  
Jul 28 11:40:41 vishalmysql1 -wsrep-sst-donor: Encrypting with CERT: /var/lib/mysql/CERTS/server-cert.pem, KEY: /var/lib/mysql/CERTS/server-key.pem, CA: /var/lib/mysql/CERTS/ca.pem  
Jul 28 11:40:41 vishalmysql1 -wsrep-sst-donor: Bypassing the SST for IST  
Jul 28 11:40:41 vishalmysql1 -wsrep-sst-donor: Evaluating xbstream -c ${INFO\_FILE} ${IST\_FILE} | socat -u stdio openssl-connect:vishalmysql2:4444,cert=/var/lib/mysql/CERTS/server-cert.pem,key=/var/lib/mysql/CERTS/server-key.pem,cafile=/var/lib/mysql/CERTS/ca.pem,verify=1; RC=( ${PIPESTATUS[@]} )  
Jul 28 11:40:41 vishalmysql1 mysqld: 2017-07-28 11:40:41 23619 [ERROR] WSREP: sst sent called when not SST donor, state JOINED  
Jul 28 11:40:41 vishalmysql1 -wsrep-sst-donor: Total time on donor: 0 seconds  
Jul 28 11:40:41 vishalmysql1 -wsrep-sst-donor: Cleaning up temporary directories  
Jul 28 11:40:41 vishalmysql1 mysqld: 2017-07-28 11:40:41 23619 [Note] WSREP: forgetting 1ac12fce (ssl://172.28.96.198:4567)  
Jul 28 11:40:41 vishalmysql1 mysqld: 2017-07-28 11:40:41 23619 [Note] WSREP: Node ea1a47da state prim

Any idea ?
