<div dir="ltr"><div class="gmail_default" style="font-family:arial,helvetica,sans-serif"><br></div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, May 10, 2017 at 9:13 AM, Juan Hernández <span dir="ltr"><<a href="mailto:jhernand@redhat.com" target="_blank">jhernand@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 05/10/2017 09:07 AM, Yaniv Kaul wrote:<br>
><br>
><br>
> On Wed, May 10, 2017 at 9:35 AM, Martin Perina <<a href="mailto:mperina@redhat.com">mperina@redhat.com</a><br>
> <mailto:<a href="mailto:mperina@redhat.com">mperina@redhat.com</a>>> wrote:<br>
><br>
> Does this mean that we need to create new CA for all existing oVirt<br>
> installations which are not using custom HTTPS certificate signed by<br>
> external CA?<br>
><br>
><br>
> No, just a new certificate for Engine, I believe.<br>
> Y.<br>
><br>
<br>
Probably not even for the engine, but just for the web server.<br></blockquote><div><br><div style="font-family:arial,helvetica,sans-serif;display:inline" class="gmail_default">@Sandro/@Didi: do we</div> <div style="font-family:arial,helvetica,sans-serif;display:inline" class="gmail_default">have some documentation how to create new engine HTTPS certificate signed by oVirt internal CA with subjectAltName properly set?<br><br></div></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
><br>
> On Sun, May 7, 2017 at 7:37 PM, Nir Soffer <<a href="mailto:nsoffer@redhat.com">nsoffer@redhat.com</a><br>
> <mailto:<a href="mailto:nsoffer@redhat.com">nsoffer@redhat.com</a>>> wrote:<br>
><br>
> On Sun, May 7, 2017 at 8:27 PM Dan Kenigsberg <<a href="mailto:danken@redhat.com">danken@redhat.com</a><br>
> <mailto:<a href="mailto:danken@redhat.com">danken@redhat.com</a>>> wrote:<br>
><br>
> On Sun, May 7, 2017 at 8:22 PM, Nir Soffer<br>
> <<a href="mailto:nsoffer@redhat.com">nsoffer@redhat.com</a> <mailto:<a href="mailto:nsoffer@redhat.com">nsoffer@redhat.com</a>>> wrote:<br>
> > I imported the certificate from my engine into chrome[1],<br>
> but Chrome<br>
> > refuses to use it because:<br>
> ><br>
> > This server could not prove that it is ...; its security<br>
> > certificate is from [missing_subjectAltName].<br>
> ><br>
> > Same certificate used to work 2 weeks ago, looks like new<br>
> Chrome<br>
> > version changed the rules.<br>
> ><br>
> > Without importing engine CA, there is no way to upload images<br>
> > via engine.<br>
> ><br>
> > Tested on engine 4.1.1 and 4.1.2 on Centos 7.3.<br>
> ><br>
> > Is this known issue?<br>
> ><br>
> > [1] from<br>
> ><br>
> http://<engine_url>/ovirt-<wbr>engine/services/pki-resource?<wbr>resource=ca-certificate&<wbr>format=X509-PEM-CA<br>
> ><br>
> > Nir<br>
><br>
> <a href="https://gerrit.ovirt.org/#/c/74614/" rel="noreferrer" target="_blank">https://gerrit.ovirt.org/#/c/<wbr>74614/</a><br>
> <<a href="https://gerrit.ovirt.org/#/c/74614/" rel="noreferrer" target="_blank">https://gerrit.ovirt.org/#/c/<wbr>74614/</a>><br>
><br>
> "This patch is not yet working, but can be used for discussion."<br>
><br>
><br>
> Thanks!<br>
><br>
> Do you know how to manually fix engine certificates until we<br>
> have a working<br>
> patch?<br>
><br>
> Nir<br>
><br>
> ______________________________<wbr>_________________<br>
> Devel mailing list<br>
> <a href="mailto:Devel@ovirt.org">Devel@ovirt.org</a> <mailto:<a href="mailto:Devel@ovirt.org">Devel@ovirt.org</a>><br>
> <a href="http://lists.ovirt.org/mailman/listinfo/devel" rel="noreferrer" target="_blank">http://lists.ovirt.org/<wbr>mailman/listinfo/devel</a><br>
> <<a href="http://lists.ovirt.org/mailman/listinfo/devel" rel="noreferrer" target="_blank">http://lists.ovirt.org/<wbr>mailman/listinfo/devel</a>><br>
><br>
><br>
><br>
> ______________________________<wbr>_________________<br>
> Devel mailing list<br>
> <a href="mailto:Devel@ovirt.org">Devel@ovirt.org</a> <mailto:<a href="mailto:Devel@ovirt.org">Devel@ovirt.org</a>><br>
> <a href="http://lists.ovirt.org/mailman/listinfo/devel" rel="noreferrer" target="_blank">http://lists.ovirt.org/<wbr>mailman/listinfo/devel</a><br>
> <<a href="http://lists.ovirt.org/mailman/listinfo/devel" rel="noreferrer" target="_blank">http://lists.ovirt.org/<wbr>mailman/listinfo/devel</a>><br>
><br>
><br>
><br>
><br>
> ______________________________<wbr>_________________<br>
> Devel mailing list<br>
> <a href="mailto:Devel@ovirt.org">Devel@ovirt.org</a><br>
> <a href="http://lists.ovirt.org/mailman/listinfo/devel" rel="noreferrer" target="_blank">http://lists.ovirt.org/<wbr>mailman/listinfo/devel</a><br>
><br>
<br>
</blockquote></div><br></div></div>