<br><div class="gmail_extra"><br><br><div class="gmail_quote">On Thu, Dec 13, 2012 at 1:21 PM, David Jaša <span dir="ltr">&lt;<a href="mailto:djasa@redhat.com" target="_blank">djasa@redhat.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">

Cristian Falcas píše v Čt 13. 12. 2012 v 12:43 +0200:<br>
<div><div class="h5">&gt;<br>
&gt;<br>
&gt;<br>
&gt; On Thu, Dec 13, 2012 at 2:07 AM, Alon Bar-Lev &lt;<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>&gt; wrote:<br>
&gt;<br>
&gt;<br>
&gt;         ----- Original Message -----<br>
&gt;         &gt; From: &quot;Cristian Falcas&quot; &lt;<a href="mailto:cristi.falcas@gmail.com">cristi.falcas@gmail.com</a>&gt;<br>
&gt;<br>
&gt;         &gt; To: &quot;Alon Bar-Lev&quot; &lt;<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>&gt;<br>
&gt;         &gt; Cc: &quot;Roy Golan&quot; &lt;<a href="mailto:rgolan@redhat.com">rgolan@redhat.com</a>&gt;, <a href="mailto:users@ovirt.org">users@ovirt.org</a>, &quot;Juan Antonio Hernandez Fernandez&quot; &lt;<a href="mailto:jhernand@redhat.com">jhernand@redhat.com</a>&gt;,<br>


&gt;         &gt; &quot;David Jaša&quot; &lt;<a href="mailto:djasa@redhat.com">djasa@redhat.com</a>&gt;, &quot;Itamar Heim&quot; &lt;<a href="mailto:iheim@redhat.com">iheim@redhat.com</a>&gt;<br>
&gt;         &gt; Sent: Thursday, December 13, 2012 2:01:22 AM<br>
&gt;         &gt; Subject: Re: Spice issues with latest vdsm (was Re: [Users] Cannot find suitable CPU model for given data)<br>
&gt;         &gt;<br>
&gt;         &gt;<br>
&gt;         &gt;<br>
&gt;         &gt;<br>
&gt;         &gt;<br>
&gt;         &gt;<br>
&gt;<br>
&gt;         &gt; On Thu, Dec 13, 2012 at 12:13 AM, Alon Bar-Lev &lt; <a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a> &gt;<br>
&gt;         &gt; wrote:<br>
&gt;         &gt;<br>
&gt;         &gt;<br>
&gt;         &gt;<br>
&gt;         &gt;<br>
&gt;         &gt;<br>
&gt;         &gt; ----- Original Message -----<br>
&gt;         &gt; &gt; From: &quot;Cristian Falcas&quot; &lt; <a href="mailto:cristi.falcas@gmail.com">cristi.falcas@gmail.com</a> &gt;<br>
&gt;         &gt; &gt; To: &quot;Itamar Heim&quot; &lt; <a href="mailto:iheim@redhat.com">iheim@redhat.com</a> &gt;<br>
&gt;<br>
&gt;         &gt; &gt; Cc: &quot;Roy Golan&quot; &lt; <a href="mailto:rgolan@redhat.com">rgolan@redhat.com</a> &gt;, <a href="mailto:users@ovirt.org">users@ovirt.org</a> , &quot;Alon<br>
&gt;         &gt; &gt; Bar-Lev&quot; &lt; <a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a> &gt;, &quot;Juan Antonio Hernandez<br>
&gt;         &gt; &gt; Fernandez&quot; &lt; <a href="mailto:jhernand@redhat.com">jhernand@redhat.com</a> &gt;, &quot;David Jaša&quot; &lt; <a href="mailto:djasa@redhat.com">djasa@redhat.com</a><br>
&gt;         &gt; &gt; &gt;<br>
&gt;         &gt; &gt; Sent: Wednesday, December 12, 2012 11:21:32 PM<br>
&gt;         &gt; &gt; Subject: Re: Spice issues with latest vdsm (was Re: [Users] Cannot<br>
&gt;         &gt; &gt; find suitable CPU model for given data)<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt; On Wed, Dec 12, 2012 at 11:14 PM, Itamar Heim &lt; <a href="mailto:iheim@redhat.com">iheim@redhat.com</a> &gt;<br>
&gt;         &gt; &gt; wrote:<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt; On 12/12/2012 10:39 PM, Cristian Falcas wrote:<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt; Hi,<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt; i don&#39;t know if I should start a new thread for the spice problems.<br>
&gt;         &gt; &gt; Here<br>
&gt;         &gt; &gt; goes some improvements:<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt; I created the certificates like per <a href="https://gist.github.com/" target="_blank">https://gist.github.com/</a><br>
&gt;         &gt; &gt; 1655511<br>
&gt;         &gt; &gt; . i<br>
&gt;         &gt; &gt; copied the public one to my home:<br>
&gt;         &gt; &gt; cp /etc/pki/vdsm/libvirt-spice/ ca-cert.pem<br>
&gt;         &gt; &gt; ~cristi/.spice/spice_ truststore.pem<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt; I had the same problem as in<br>
&gt;         &gt; &gt; <a href="https://bugzilla.redhat.com/" target="_blank">https://bugzilla.redhat.com/</a> show_bug.cgi?id=880182 . For this I<br>
&gt;         &gt;<br>
&gt;         &gt; &gt; needed<br>
&gt;         &gt; &gt; to downgrade libcacard twice (until I had the same version as in<br>
&gt;         &gt; &gt; the<br>
&gt;         &gt; &gt; bug)<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt; Now spice works with virt-manager.<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt; Can someone tell me where do I need to copy the certificate on<br>
&gt;         &gt; &gt; ovirt<br>
&gt;         &gt; &gt; in<br>
&gt;         &gt; &gt; order to make spice working over there also?<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt; with which version of boostrap on the engine did you add this host.<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt; vdsm-bootstrap-4.10.3-0.3.git47b71e8.fc17.noarch<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt; And otopi packages installed:<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt; otopi-0.0.0-0.5.master.20121211.git9052d0f.fc17.noarch<br>
&gt;         &gt; &gt; otopi-java-0.0.0-0.5.master.20121211.git9052d0f.fc17.noarch<br>
&gt;         &gt; &gt;<br>
&gt;         &gt; &gt;<br>
&gt;         &gt;<br>
&gt;         &gt; Any reason to perform certificate enrollment manually?<br>
&gt;         &gt;<br>
&gt;         &gt; Alon<br>
&gt;         &gt;<br>
&gt;         &gt;<br>
&gt;         &gt; It&#39;s still not working with the handmade certificates.<br>
&gt;         &gt;<br>
&gt;         &gt; I tried to create them because of those errors:<br>
&gt;         &gt;<br>
&gt;         &gt; libvirt log:<br>
&gt;         &gt;<br>
&gt;         &gt; ((null):9248): Spice-Warning **: reds.c:3307:reds_init_ssl: Could not<br>
&gt;         &gt; load certificates from /etc/pki/vdsm/libvirt-spice/<br>
&gt;         &gt; server-cert.pem<br>
&gt;         &gt; ((null):9248): Spice-Warning **: reds.c:3317:reds_init_ssl: Could not<br>
&gt;         &gt; use private key file<br>
&gt;         &gt; ((null):9248): Spice-Warning **: reds.c:3325:reds_init_ssl: Could not<br>
&gt;         &gt; use CA file /etc/pki/vdsm/libvirt-spice/ca-cert.pem<br>
&gt;         &gt;<br>
&gt;         &gt; [root@localhost Ovirt]# ls -la<br>
&gt;         &gt; /etc/pki/vdsm/libvirt-spice/server-cert.pem<br>
&gt;         &gt; ls: cannot access /etc/pki/vdsm/libvirt-spice/server-cert.pem: No<br>
&gt;         &gt; such file or directory<br>
&gt;         &gt; [root@localhost Ovirt]# ls -la<br>
&gt;         &gt; /etc/pki/vdsm/libvirt-spice/ca-cert.pem<br>
&gt;         &gt; ls: cannot access /etc/pki/vdsm/libvirt-spice/ca-cert.pem: No such<br>
&gt;         &gt; file or directory<br>
&gt;         &gt;<br>
&gt;         &gt;<br>
&gt;         &gt; Spice log:<br>
&gt;         &gt;<br>
&gt;         &gt; 1355334879 INFO [8950:8950] Application::main: starting 0.12.0<br>
&gt;         &gt; 1355334879 INFO [8950:8950] Application::main: command line: spicec<br>
&gt;         &gt; --controller<br>
&gt;         &gt; 1355334879 INFO [8950:8950] init_key_map: using evdev mapping<br>
&gt;         &gt; 1355334879 INFO [8950:8950] MultyMonScreen::MultyMonScreen:<br>
&gt;         &gt; platform_win: 77594625<br>
&gt;         &gt; 1355334879 INFO [8950:8950] GUI::GUI:<br>
&gt;         &gt; 1355334879 INFO [8950:8950] ForeignMenu::ForeignMenu: Creating a<br>
&gt;         &gt; foreign menu connection /tmp/SpiceForeignMenu-8950.uds<br>
&gt;         &gt; 1355334879 INFO [8950:8950] Controller::Controller: Creating a<br>
&gt;         &gt; controller connection /tmp/spicec-9GS5mA/spice-xpi<br>
&gt;         &gt; 1355334882 INFO [8950:8952] RedPeer::connect_secure: Connected to<br>
&gt;         &gt; <a href="http://cristifalcas.no-ip.org" target="_blank">cristifalcas.no-ip.org</a> 5902<br>
&gt;         &gt; 1355334882 ERROR [8950:8952] RedPeer::connect_secure: failed to<br>
&gt;         &gt; connect w/SSL, ssl_error error:00000001:lib(0):func(0):reason(1)<br>
&gt;         &gt; 1355334882 WARN [8950:8952] RedChannel::run: SSL Error:<br>
&gt;         &gt; error:14094410:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake<br>
&gt;         &gt; failure<br>
&gt;         &gt; 1355334882 INFO [8950:8950] main: Spice client terminated (exitcode =<br>
&gt;         &gt; 7)<br>
&gt;         &gt;<br>
&gt;         &gt;<br>
&gt;         &gt;<br>
&gt;         &gt;<br>
&gt;         &gt; I&#39;ve done this without an improvment:<br>
&gt;         &gt;<br>
&gt;         &gt; [root@localhost Ovirt]# /lib/systemd/systemd-vdsmd reconfigure<br>
&gt;         &gt; Configuring libvirt for vdsm...<br>
&gt;         &gt; [root@localhost Ovirt]# systemctl restart libvirtd.service<br>
&gt;         &gt; vdsmd.service<br>
&gt;         &gt;<br>
&gt;<br>
&gt;<br>
&gt;         Why don&#39;t you deply the host again? It should create the certificate correctly.<br>
&gt;<br>
&gt;         But before you can do this, you must remove whatever certificates you put including symlinks at /etc/pki /etc/libvirt as libvirt will not start if there are invalid certificates.<br>
&gt;<br>
&gt;         Alon.<br>
&gt;<br>
&gt; I already did this. Also, i removed all configuration files from host and ovirt, reinstalled ovirt-engine, removed vdsm,libvirt,qemu on host.<br>
&gt;<br>
&gt; I still got this when I start the machine:<br>
&gt; ((null):5004): Spice-Warning **: reds.c:3307:reds_init_ssl: Could not load certificates from /etc/pki/vdsm/libvirt-spice/server-cert.pem<br>
&gt; ((null):5004): Spice-Warning **: reds.c:3317:reds_init_ssl: Could not use private key file<br>
&gt; ((null):5004): Spice-Warning **: reds.c:3325:reds_init_ssl: Could not use CA file /etc/pki/vdsm/libvirt-spice/ca-cert.pem<br>
&gt;<br>
&gt; And this when I try to connect:<br>
&gt;<br>
&gt; ((null):5004): Spice-Warning **: reds.c:2913:reds_handle_ssl_accept: SSL_accept failed, error=1<br>
<br>
</div></div>Didn&#39;t you disable encryption on engine or in vdsm.conf? Unfortunately, it is still interdependent with spice encryption setup.<br>
<br>
(and a side question: if so, why did you disable it? oVirt takes care of it without any extra work so I see no benefit in it)<br>
<br>
David<br>
<br>
PS: please send mails in plain text<br>
<br>
&gt;<br>
&gt; Best regards,<br>
&gt; Cristian falcas<br>
&gt;<br>
&gt; _______________________________________________<br>
&gt; Users mailing list<br>
&gt; <a href="mailto:Users@ovirt.org">Users@ovirt.org</a><br>
&gt; <a href="http://lists.ovirt.org/mailman/listinfo/users" target="_blank">http://lists.ovirt.org/mailman/listinfo/users</a><br>
<span class=""><font color="#888888"><br>
--<br>
<br>
David Jaša, RHCE<br>
<br>
SPICE QE based in Brno<br>
GPG Key:     22C33E24<br>
Fingerprint: 513A 060B D1B4 2A72 7F0D 0278 B125 CD00 22C3 3E24<br>
<br>
<br>
<br>
</font></span></blockquote></div><br>I didn&#39;t touched anything this time.<br><br>[cristi@localhost ~]$ cat /etc/vdsm/vdsm.conf<br>[vars]<br>ssl = true<br><br>[addresses]<br>management_port = 54321<br><br><br>qemu:<br>

## beginning of configuration section by vdsm-4.9.11<br>dynamic_ownership=0<br>spice_tls=1<br>save_image_format=&quot;lzop&quot;<br>spice_tls_x509_cert_dir=&quot;/etc/pki/vdsm/libvirt-spice&quot;<br>lock_manager=&quot;sanlock&quot;<br>

auto_dump_path=&quot;/var/log/core&quot;<br>## end of configuration section by vdsm-4.9.11<br><br>libvirtd:<br>## beginning of configuration section by vdsm-4.9.11<br>listen_addr=&quot;0.0.0.0&quot;<br>unix_sock_group=&quot;kvm&quot;<br>

unix_sock_rw_perms=&quot;0770&quot;<br>auth_unix_rw=&quot;sasl&quot;<br>host_uuid=&quot;ac7ce924-3da8-41a5-9fa5-03af184b0437&quot;<br>log_outputs=&quot;1:file:/var/log/libvirtd.log&quot;<br>log_filters=&quot;1:libvirt 3:event 3:json 1:util 1:qemu&quot;<br>

ca_file=&quot;/etc/pki/vdsm/certs/cacert.pem&quot;<br>cert_file=&quot;/etc/pki/vdsm/certs/vdsmcert.pem&quot;<br>key_file=&quot;/etc/pki/vdsm/keys/vdsmkey.pem&quot;<br>## end of configuration section by vdsm-4.9.11<br><br>

</div>