Existing server certificate with different name "ip-172-31-8-25" already in trust store

I have 2 servers one o them main and other backup. I try to create cluster with command lxd init.
With main server is everything ok

lxc --version
4.23
root@ip-172-31-2-75:/var/snap/lxd/common/lxd# lxc cluster list
+-------------+--------------------------+-----------------+--------------+----------------+-------------+--------+-------------------+
|    NAME     |           URL            |      ROLES      | ARCHITECTURE | FAILURE DOMAIN | DESCRIPTION | STATE  |      MESSAGE      |
+-------------+--------------------------+-----------------+--------------+----------------+-------------+--------+-------------------+
| devel-lxd01 | https://172.31.2.75:8443 | database-leader | x86_64       | default        |             | ONLINE | Fully operational |
|             |                          | database        |              |                |             |        |                   |
+-------------+--------------------------+-----------------+--------------+----------------+-------------+--------+-------------------+

But when I try connect my backup server to cluster I got error:

 lxd init
Would you like to use LXD clustering? (yes/no) [default=no]: yes
What IP address or DNS name should be used to reach this node? [default=172.31.8.25]:
Are you joining an existing cluster? (yes/no) [default=no]: yes
Do you have a join token? (yes/no/[token]) [default=no]:
What name should be used to identify this node in the cluster? [default=ip-172-31-8-25]: devel-lxd02
IP address or FQDN of an existing cluster member: 172.31.2.75
Cluster fingerprint: 0ff352014fcafe7fe7487339fa5326e4a42559e983eaf6ef4cd3498cb666b7d3
You can validate this fingerprint by running "lxc info" locally on an existing node.
Is this the correct fingerprint? (yes/no/[fingerprint]) [default=no]: yes
Cluster trust password:
All existing data is lost when joining a cluster, continue? (yes/no) [default=no] yes
Choose "source" property for storage pool "local": 7GB
Choose "zfs.pool_name" property for storage pool "local":
Choose "size" property for storage pool "local":
Would you like a YAML "lxd init" preseed to be printed? (yes/no) [default=no]:

Error: Failed to join cluster: Failed to update cluster trust: Existing server certificate with different name "ip-172-31-8-25" already in trust store

Info:

root@ip-172-31-2-75:/var/snap/lxd/common/lxd# lxc config trust list
+--------+----------------+---------------------+--------------+------------------------------+------------------------------+
|  TYPE  |      NAME      |     COMMON NAME     | FINGERPRINT  |          ISSUE DATE          |         EXPIRY DATE          |
+--------+----------------+---------------------+--------------+------------------------------+------------------------------+
| server | devel-lxd01    | root@ip-172-31-2-75 | 10e9332ad73a | Mar 7, 2022 at 9:44am (UTC)  | Mar 4, 2032 at 9:44am (UTC)  |
+--------+----------------+---------------------+--------------+------------------------------+------------------------------+
| server | ip-172-31-8-25 | root@ip-172-31-8-25 | b2d9cedc106e | Mar 7, 2022 at 10:25am (UTC) | Mar 4, 2032 at 10:25am (UTC) |
+--------+----------------+---------------------+--------------+------------------------------+------------------------------+
root@ip-172-31-2-75:/var/snap/lxd/common/lxd# lxd sql global "SELECT * FROM certificates;"
+----+------------------------------------------------------------------+------+----------------+------------------------------------------------------------------+------------+
| id |                           fingerprint                            | type |      name      |                           certificate                            | restricted |
+----+------------------------------------------------------------------+------+----------------+------------------------------------------------------------------+------------+
| 1  | 10e9332ad73a639e4690f1f0c3af0fc930e0b80e8a31741b9d863541b3179030 | 2    | devel-lxd01    | -----BEGIN CERTIFICATE-----                                      | 0          |
|    |                                                                  |      |                | MIICHDCCAaKgAwIBAgIRAOfu1JpoZfYX4K+iFGc4KaowCgYIKoZIzj0EAwMwPDEc |            |
|    |                                                                  |      |                | MBoGA1UEChMTbGludXhjb250YWluZXJzLm9yZzEcMBoGA1UEAwwTcm9vdEBpcC0x |            |
|    |                                                                  |      |                | NzItMzEtMi03NTAeFw0yMjAzMDcwOTQ0MjBaFw0zMjAzMDQwOTQ0MjBaMDwxHDAa |            |
|    |                                                                  |      |                | BgNVBAoTE2xpbnV4Y29udGFpbmVycy5vcmcxHDAaBgNVBAMME3Jvb3RAaXAtMTcy |            |
|    |                                                                  |      |                | LTMxLTItNzUwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQUp8HfW1p0dyt17OBMJShC |            |
|    |                                                                  |      |                | NyDpOf2/onbWjKcq2r4KcWKy5RB13/ckITV40bQ3vS841xOFHqqm1wknmY5RSsvx |            |
|    |                                                                  |      |                | H9LBocrZr8GTEj9vG0EiFmWACbS1L5BOZvkDNUweq+KjaDBmMA4GA1UdDwEB/wQE |            |
|    |                                                                  |      |                | AwIFoDATBgNVHSUEDDAKBggrBgEFBQcDATAMBgNVHRMBAf8EAjAAMDEGA1UdEQQq |            |
|    |                                                                  |      |                | MCiCDmlwLTE3Mi0zMS0yLTc1hwR/AAABhxAAAAAAAAAAAAAAAAAAAAABMAoGCCqG |            |
|    |                                                                  |      |                | SM49BAMDA2gAMGUCMB+mOxa6eWT3GYsB1zmyvUhJhAXxDHTXUNvU1Re9mnXuVNgd |            |
|    |                                                                  |      |                | D2lBQj9aDhxvllB+tQIxAMP8HPfRV67NWl1DTkvJJg8VT6eSQTPWPQQPWDe9pIkt |            |
|    |                                                                  |      |                | pU2WheRPfxvTEHMtOjXYBg==                                         |            |
|    |                                                                  |      |                | -----END CERTIFICATE-----                                        |            |
|    |                                                                  |      |                |                                                                  |            |
| 4  | b2d9cedc106ef6948db46b86127e833562639339cb3512eb181e4a30504e87f7 | 2    | ip-172-31-8-25 | -----BEGIN CERTIFICATE-----                                      | 0          |
|    |                                                                  |      |                | MIICGzCCAaGgAwIBAgIQelSt4yTKu0s4Lnkjjpn29DAKBggqhkjOPQQDAzA8MRww |            |
|    |                                                                  |      |                | GgYDVQQKExNsaW51eGNvbnRhaW5lcnMub3JnMRwwGgYDVQQDDBNyb290QGlwLTE3 |            |
|    |                                                                  |      |                | Mi0zMS04LTI1MB4XDTIyMDMwNzEwMjU0OFoXDTMyMDMwNDEwMjU0OFowPDEcMBoG |            |
|    |                                                                  |      |                | A1UEChMTbGludXhjb250YWluZXJzLm9yZzEcMBoGA1UEAwwTcm9vdEBpcC0xNzIt |            |
|    |                                                                  |      |                | MzEtOC0yNTB2MBAGByqGSM49AgEGBSuBBAAiA2IABEloVVpBDgl17hc/FlRsngdj |            |
|    |                                                                  |      |                | wBP455YtjxMG02YalRRhvS7y9UXZcfeDzlk/L6T0vc8efalSiPBxToS3A3qDT4/0 |            |
|    |                                                                  |      |                | Fpz9t735e+KNWJGHEkSCvaFkAIg5tBgFef+cF9butaNoMGYwDgYDVR0PAQH/BAQD |            |
|    |                                                                  |      |                | AgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAwGA1UdEwEB/wQCMAAwMQYDVR0RBCow |            |
|    |                                                                  |      |                | KIIOaXAtMTcyLTMxLTgtMjWHBH8AAAGHEAAAAAAAAAAAAAAAAAAAAAEwCgYIKoZI |            |
|    |                                                                  |      |                | zj0EAwMDaAAwZQIxAJAiKVjK16pC9Q5ZCXTkmGXJ5RpHnluxt5jbv+V9AfB7Kx8G |            |
|    |                                                                  |      |                | uWlHM8VQnL9lkgxYLgIwKLJwMyaD2zndJU53yEdhXsf+a/pIFw/pbu/QIBLZ4oKJ |            |
|    |                                                                  |      |                | hbp3whE6RW1HRq7L55YZ                                             |            |
|    |                                                                  |      |                | -----END CERTIFICATE-----                                        |            |
|    |                                                                  |      |                |                                                                  |            |
+----+------------------------------------------------------------------+------+----------------+------------------------------------------------------------------+------------+

Could you help please. I tried 3 or 4 time, reinstall new OS and new volumes, but error the same. I do not understand why O_0

Assuming it’s not in lxc cluster list, you could do lxd sql global "DELETE FROM certificates WHERE fingerprint='b2d9cedc106ef6948db46b86127e833562639339cb3512eb181e4a30504e87f7' to clear it

I reinstall my OS, and tried to use your command: new IP 172.31.14.207 main server and 172.31.15.205 - backup

root@ip-172-31-14-207:/home/ubuntu# lxd sql global "DELETE FROM certificates WHERE fingerprint='7057276ee4cc8b6838a6eba039fe37f42f1bccef8e326866964e2af740fcbebd';"
Rows affected: 1
root@ip-172-31-14-207:/home/ubuntu# lxd sql global "SELECT * FROM certificates;"
+----+------------------------------------------------------------------+------+-------------+------------------------------------------------------------------+------------+
| id |                           fingerprint                            | type |    name     |                           certificate                            | restricted |
+----+------------------------------------------------------------------+------+-------------+------------------------------------------------------------------+------------+
| 1  | 792e73c7c8dd41ac22ff617fc64e3c72354126a4ab3beb6ebcc372a0cb8daefe | 2    | devel-lxd01 | -----BEGIN CERTIFICATE-----                                      | 0          |
|    |                                                                  |      |             | MIICIzCCAaigAwIBAgIRANvnl27y/I8mDUJkg3ZyjS4wCgYIKoZIzj0EAwMwPjEc |            |
|    |                                                                  |      |             | MBoGA1UEChMTbGludXhjb250YWluZXJzLm9yZzEeMBwGA1UEAwwVcm9vdEBpcC0x |            |
|    |                                                                  |      |             | NzItMzEtMTQtMjA3MB4XDTIyMDMwNzE1MzkwMFoXDTMyMDMwNDE1MzkwMFowPjEc |            |
|    |                                                                  |      |             | MBoGA1UEChMTbGludXhjb250YWluZXJzLm9yZzEeMBwGA1UEAwwVcm9vdEBpcC0x |            |
|    |                                                                  |      |             | NzItMzEtMTQtMjA3MHYwEAYHKoZIzj0CAQYFK4EEACIDYgAEPWoD1wAKPOKJ8MVY |            |
|    |                                                                  |      |             | nnvo+bgJLAgewR4FdxF1BYIwntX4FE1/EXpi4lx6DBgJVtzLFb+73Av34p/x055y |            |
|    |                                                                  |      |             | Sg3pTBvyt292gI+bAGip8YO+ha1hWyXdZ9gmF8X2vvT8VGHio2owaDAOBgNVHQ8B |            |
|    |                                                                  |      |             | Af8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwDAYDVR0TAQH/BAIwADAzBgNV |            |
|    |                                                                  |      |             | HREELDAqghBpcC0xNzItMzEtMTQtMjA3hwR/AAABhxAAAAAAAAAAAAAAAAAAAAAB |            |
|    |                                                                  |      |             | MAoGCCqGSM49BAMDA2kAMGYCMQCozLT/zPZ3whhSU3MxUN24kz4H5BZqhcLy5TXY |            |
|    |                                                                  |      |             | zCj1JjmrcuRHg/BkW5HQDQKNO54CMQDi7xkQScziZrKfVxQuV7Go+SErB9ZLKUqL |            |
|    |                                                                  |      |             | 4O5/YUsXpfn1pBCU397Pd17BFESYkBA=                                 |            |
|    |                                                                  |      |             | -----END CERTIFICATE-----                                        |            |
|    |                                                                  |      |             |                                                                  |            |
+----+------------------------------------------------------------------+------+-------------+------------------------------------------------------------------+------------+

But this is does not help:


root@ip-172-31-15-205:/home/ubuntu# lxd init
Would you like to use LXD clustering? (yes/no) [default=no]: yes
What IP address or DNS name should be used to reach this node? [default=172.31.15.205]:
Are you joining an existing cluster? (yes/no) [default=no]: yes
Do you have a join token? (yes/no/[token]) [default=no]:
What name should be used to identify this node in the cluster? [default=ip-172-31-15-205]: devel-lxd02
IP address or FQDN of an existing cluster member: 172.31.14.207
Cluster fingerprint: 3d298ed730bd0e2a6bf17e32e04d38b7ec7ed886f50b0662da003acc56b7d2a3
You can validate this fingerprint by running "lxc info" locally on an existing node.
Is this the correct fingerprint? (yes/no/[fingerprint]) [default=no]: yes
Cluster trust password:
All existing data is lost when joining a cluster, continue? (yes/no) [default=no] yes
Choose "size" property for storage pool "local":
Choose "source" property for storage pool "local":
Choose "zfs.pool_name" property for storage pool "local":
Would you like a YAML "lxd init" preseed to be printed? (yes/no) [default=no]:
Error: Failed to join cluster: Failed to update cluster trust: Existing server certificate with different name "ip-172-31-15-205" already in trust store

And after that I again have fingerprint and certificate my backup server in DB:

root@ip-172-31-14-207:/home/ubuntu# lxd sql global "SELECT * FROM certificates;"
+----+------------------------------------------------------------------+------+------------------+------------------------------------------------------------------+------------+
| id |                           fingerprint                            | type |       name       |                           certificate                            | restricted |
+----+------------------------------------------------------------------+------+------------------+------------------------------------------------------------------+------------+
| 1  | 792e73c7c8dd41ac22ff617fc64e3c72354126a4ab3beb6ebcc372a0cb8daefe | 2    | devel-lxd01      | -----BEGIN CERTIFICATE-----                                      | 0          |
|    |                                                                  |      |                  | MIICIzCCAaigAwIBAgIRANvnl27y/I8mDUJkg3ZyjS4wCgYIKoZIzj0EAwMwPjEc |            |
|    |                                                                  |      |                  | MBoGA1UEChMTbGludXhjb250YWluZXJzLm9yZzEeMBwGA1UEAwwVcm9vdEBpcC0x |            |
|    |                                                                  |      |                  | NzItMzEtMTQtMjA3MB4XDTIyMDMwNzE1MzkwMFoXDTMyMDMwNDE1MzkwMFowPjEc |            |
|    |                                                                  |      |                  | MBoGA1UEChMTbGludXhjb250YWluZXJzLm9yZzEeMBwGA1UEAwwVcm9vdEBpcC0x |            |
|    |                                                                  |      |                  | NzItMzEtMTQtMjA3MHYwEAYHKoZIzj0CAQYFK4EEACIDYgAEPWoD1wAKPOKJ8MVY |            |
|    |                                                                  |      |                  | nnvo+bgJLAgewR4FdxF1BYIwntX4FE1/EXpi4lx6DBgJVtzLFb+73Av34p/x055y |            |
|    |                                                                  |      |                  | Sg3pTBvyt292gI+bAGip8YO+ha1hWyXdZ9gmF8X2vvT8VGHio2owaDAOBgNVHQ8B |            |
|    |                                                                  |      |                  | Af8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwDAYDVR0TAQH/BAIwADAzBgNV |            |
|    |                                                                  |      |                  | HREELDAqghBpcC0xNzItMzEtMTQtMjA3hwR/AAABhxAAAAAAAAAAAAAAAAAAAAAB |            |
|    |                                                                  |      |                  | MAoGCCqGSM49BAMDA2kAMGYCMQCozLT/zPZ3whhSU3MxUN24kz4H5BZqhcLy5TXY |            |
|    |                                                                  |      |                  | zCj1JjmrcuRHg/BkW5HQDQKNO54CMQDi7xkQScziZrKfVxQuV7Go+SErB9ZLKUqL |            |
|    |                                                                  |      |                  | 4O5/YUsXpfn1pBCU397Pd17BFESYkBA=                                 |            |
|    |                                                                  |      |                  | -----END CERTIFICATE-----                                        |            |
|    |                                                                  |      |                  |                                                                  |            |
| 5  | 7057276ee4cc8b6838a6eba039fe37f42f1bccef8e326866964e2af740fcbebd | 2    | ip-172-31-15-205 | -----BEGIN CERTIFICATE-----                                      | 0          |
|    |                                                                  |      |                  | MIICITCCAaigAwIBAgIRAOg61UOTgUKiEInFw7KsjCgwCgYIKoZIzj0EAwMwPjEc |            |
|    |                                                                  |      |                  | MBoGA1UEChMTbGludXhjb250YWluZXJzLm9yZzEeMBwGA1UEAwwVcm9vdEBpcC0x |            |
|    |                                                                  |      |                  | NzItMzEtMTUtMjA1MB4XDTIyMDMwNzE1NDMzM1oXDTMyMDMwNDE1NDMzM1owPjEc |            |
|    |                                                                  |      |                  | MBoGA1UEChMTbGludXhjb250YWluZXJzLm9yZzEeMBwGA1UEAwwVcm9vdEBpcC0x |            |
|    |                                                                  |      |                  | NzItMzEtMTUtMjA1MHYwEAYHKoZIzj0CAQYFK4EEACIDYgAEf7/UqrLYRXGxgavS |            |
|    |                                                                  |      |                  | vO8j+fUAhOeVA4demiXvDGLvsCxvs4LdQUXOg5c6GiSYpD1fB7cpk25qEk/yUUR8 |            |
|    |                                                                  |      |                  | cusaVJyv7D39sr3v5Yvz3ncLXSoqxlbWDNoQSUDM1GWJk42Qo2owaDAOBgNVHQ8B |            |
|    |                                                                  |      |                  | Af8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwDAYDVR0TAQH/BAIwADAzBgNV |            |
|    |                                                                  |      |                  | HREELDAqghBpcC0xNzItMzEtMTUtMjA1hwR/AAABhxAAAAAAAAAAAAAAAAAAAAAB |            |
|    |                                                                  |      |                  | MAoGCCqGSM49BAMDA2cAMGQCMA2BPnpMdQKTTc9aJxUBzuT33ND6AFF5Zb/Ryjuo |            |
|    |                                                                  |      |                  | 1dwW1bcttZLCivS175I/xs7mNgIwYxSLz4o6J8NvqQ50HMBkFLzN0pgfE/QaHE70 |            |
|    |                                                                  |      |                  | GLV67qZjsUtX54nA1KqU8kNKW/Sf                                     |            |
|    |                                                                  |      |                  | -----END CERTIFICATE-----                                        |            |
|    |                                                                  |      |                  |                                                                  |            |
+----+------------------------------------------------------------------+------+------------------+------------------------------------------------------------------+------------+

I do not know what helped.

I change name of host (on server 172.31.15.205) to devel-lxd02.
Delete fingerprint: lxd sql global "DELETE FROM certificates WHERE fingerprint='7057276ee4cc8b6838a6eba039fe37f42f1bccef8e326866964e2af740fcbebd';"
Reboot main server
Use lxd init agian on backup server

root@devel-lxd02:/home/ubuntu# lxd init
Would you like to use LXD clustering? (yes/no) [default=no]: yes
What IP address or DNS name should be used to reach this node? [default=172.31.15.205]:
Are you joining an existing cluster? (yes/no) [default=no]: yes
Do you have a join token? (yes/no/[token]) [default=no]:
What name should be used to identify this node in the cluster? [default=devel-lxd02]:
IP address or FQDN of an existing cluster member: ip-172-31-14-207.eu-west-3.compute.internal
Cluster fingerprint: 3d298ed730bd0e2a6bf17e32e04d38b7ec7ed886f50b0662da003acc56b7d2a3
You can validate this fingerprint by running "lxc info" locally on an existing node.
Is this the correct fingerprint? (yes/no/[fingerprint]) [default=no]: yes
Cluster trust password:
All existing data is lost when joining a cluster, continue? (yes/no) [default=no] yes
Choose "size" property for storage pool "local": 7GB
Choose "source" property for storage pool "local":
Choose "zfs.pool_name" property for storage pool "local":
Would you like a YAML "lxd init" preseed to be printed? (yes/no) [default=no]:

Check cluster:

root@ip-172-31-14-207:/home/ubuntu# lxc cluster list
+-------------+----------------------------+------------------+--------------+----------------+-------------+--------+-------------------+
|    NAME     |            URL             |      ROLES       | ARCHITECTURE | FAILURE DOMAIN | DESCRIPTION | STATE  |      MESSAGE      |
+-------------+----------------------------+------------------+--------------+----------------+-------------+--------+-------------------+
| devel-lxd01 | https://172.31.14.207:8443 | database-leader  | x86_64       | default        |             | ONLINE | Fully operational |
|             |                            | database         |              |                |             |        |                   |
+-------------+----------------------------+------------------+--------------+----------------+-------------+--------+-------------------+
| devel-lxd02 | https://172.31.15.205:8443 | database-standby | x86_64       | default        |             | ONLINE | Fully operational |
+-------------+----------------------------+------------------+--------------+----------------+-------------+--------+-------------------+