<div dir="ltr"><div>I was just more curious about exactly what files/options database options/configurations in the engine had to be changed to disable SSL for this and just allow for http. I am not quite 100% on what the engine option "SSLEnabled" exactly disables SSL wise (EG: HTTP/VDSM?) or what effect the SSL_ONLY option in the websocket configuration has (by default it is set to false but only SSL works?). <br>
<br></div><div>Thus I am just curious on the underpinnings and how things are tied together and cause/effect ;-)<br></div><div><br></div>- DHC<br></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Fri, Aug 16, 2013 at 2:42 AM, Frantisek Kobzik <span dir="ltr"><<a href="mailto:fkobzik@redhat.com" target="_blank">fkobzik@redhat.com</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">I'll try to resolve that soon.<br>
<br>
Thanks,<br>
<div class="im HOEnZb">F.<br>
<br>
----- Original Message -----<br>
From: "Alon Bar-Lev" <<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>><br>
</div><div class="im HOEnZb">To: "Frantisek Kobzik" <<a href="mailto:fkobzik@redhat.com">fkobzik@redhat.com</a>><br>
Cc: "Dead Horse" <<a href="mailto:deadhorseconsulting@gmail.com">deadhorseconsulting@gmail.com</a>>, "users" <<a href="mailto:users@ovirt.org">users@ovirt.org</a>><br>
</div><div class="HOEnZb"><div class="h5">Sent: Friday, August 16, 2013 9:04:09 AM<br>
Subject: Re: [Users] Questions on ovirt 3.3 browser based spice/novnc working<br>
<br>
<br>
<br>
----- Original Message -----<br>
> From: "Frantisek Kobzik" <<a href="mailto:fkobzik@redhat.com">fkobzik@redhat.com</a>><br>
> To: "Alon Bar-Lev" <<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>><br>
> Cc: "Dead Horse" <<a href="mailto:deadhorseconsulting@gmail.com">deadhorseconsulting@gmail.com</a>>, "users" <<a href="mailto:users@ovirt.org">users@ovirt.org</a>><br>
> Sent: Friday, August 16, 2013 9:58:27 AM<br>
> Subject: Re: [Users] Questions on ovirt 3.3 browser based spice/novnc working<br>
><br>
> Hi,<br>
><br>
> exactly - the fact about the vdc option is true.<br>
><br>
> (and I think we also have to allow serving novnc/spice-html5 pages using<br>
> plain http. afaik now apache or jboss forces you to https).<br>
<br>
No... just a setting for the proxy.<br>
As the html files them-selves comes from same location of where user is on.<br>
Can you please handle that?<br>
<br>
><br>
> Regards,<br>
> F.<br>
><br>
> ----- Original Message -----<br>
> From: "Alon Bar-Lev" <<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>><br>
> To: "Dead Horse" <<a href="mailto:deadhorseconsulting@gmail.com">deadhorseconsulting@gmail.com</a>><br>
> Cc: "users" <<a href="mailto:users@ovirt.org">users@ovirt.org</a>>, "Frantisek Kobzik" <<a href="mailto:fkobzik@redhat.com">fkobzik@redhat.com</a>><br>
> Sent: Friday, August 16, 2013 8:45:05 AM<br>
> Subject: Re: [Users] Questions on ovirt 3.3 browser based spice/novnc working<br>
><br>
><br>
><br>
> ----- Original Message -----<br>
> > From: "Dead Horse" <<a href="mailto:deadhorseconsulting@gmail.com">deadhorseconsulting@gmail.com</a>><br>
> > To: "Alon Bar-Lev" <<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>><br>
> > Cc: "users" <<a href="mailto:users@ovirt.org">users@ovirt.org</a>>, "Frantisek Kobzik" <<a href="mailto:fkobzik@redhat.com">fkobzik@redhat.com</a>><br>
> > Sent: Friday, August 16, 2013 3:55:28 AM<br>
> > Subject: Re: [Users] Questions on ovirt 3.3 browser based spice/novnc<br>
> > working<br>
> ><br>
> > Curiously if one wanted the disable the need to download the Server CA<br>
> > certificate what are the changes needed to do so? (Realizing the security<br>
> > implications)<br>
><br>
> I do not understand, what alternative do you propose?<br>
><br>
> You can disable ssl.... but Frantisek, we need a vdc option for that so url<br>
> will contain http or https.<br>
><br>
> ><br>
> ><br>
> > On Fri, Aug 2, 2013 at 2:49 PM, Alon Bar-Lev <<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>> wrote:<br>
> ><br>
> > ><br>
> > ><br>
> > > ----- Original Message -----<br>
> > > > From: "Dead Horse" <<a href="mailto:deadhorseconsulting@gmail.com">deadhorseconsulting@gmail.com</a>><br>
> > > > To: "Alon Bar-Lev" <<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>><br>
> > > > Cc: "users" <<a href="mailto:users@ovirt.org">users@ovirt.org</a>><br>
> > > > Sent: Friday, August 2, 2013 10:39:48 PM<br>
> > > > Subject: Re: [Users] Questions on ovirt 3.3 browser based spice/novnc<br>
> > > working<br>
> > > ><br>
> > > > Thanks Alon,<br>
> > > > That did the trick. Is there any way to get the engine to push this<br>
> > > > cert<br>
> > > to<br>
> > > > a first time visitor by default?<br>
> > > > - DHC<br>
> > ><br>
> > > Well, it is actually depend on browser behavior... Internet Explorer does<br>
> > > allow you to trust the root.<br>
> > ><br>
> > > I could not find such option in firefox.<br>
> > ><br>
> > > Frantisek:<br>
> > ><br>
> > > Maybe we can have the link for the ca certificate so people can press it<br>
> > > to establish trust.<br>
> > ><br>
> > > Have you tried to perform XMLHttpRequest and see if you get some error we<br>
> > > can use to warn user?<br>
> > ><br>
> > > ><br>
> > > ><br>
> > > > On Fri, Aug 2, 2013 at 1:18 AM, Alon Bar-Lev <<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>> wrote:<br>
> > > ><br>
> > > > ><br>
> > > > ><br>
> > > > > ----- Original Message -----<br>
> > > > > > From: "Dead Horse" <<a href="mailto:deadhorseconsulting@gmail.com">deadhorseconsulting@gmail.com</a>><br>
> > > > > > To: "Alon Bar-Lev" <<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>><br>
> > > > > > Cc: "users" <<a href="mailto:users@ovirt.org">users@ovirt.org</a>><br>
> > > > > > Sent: Thursday, August 1, 2013 11:06:11 PM<br>
> > > > > > Subject: Re: [Users] Questions on ovirt 3.3 browser based<br>
> > > > > > spice/novnc<br>
> > > > > working<br>
> > > > > ><br>
> > > > > > Attached Firefox and Chrome screenshots of Certificates.<br>
> > > > > > errors thrown by websockify<br>
> > > > > > Firefox: 1: handler exception: [Errno 1] _ssl.c:1359:<br>
> > > error:14094418:SSL<br>
> > > > > > routines:SSL3_READ_BYTES:tlsv1 alert unknown ca<br>
> > > > > > Chrome: 11: handler exception: WSRequestHandler instance has no<br>
> > > attribute<br>
> > > > > > 'last_code'<br>
> > > > > ><br>
> > > > > > For Firefox it looks like firefox needs a bit of proding to get it<br>
> > > > > > to<br>
> > > > > > accept the Websocket CA Cert:<br>
> > > > > > <a href="https://github.com/kanaka/websockify/issues/34" target="_blank">https://github.com/kanaka/websockify/issues/34</a><br>
> > > > > ><br>
> > > > > > The error generated by chrome seems to be a websockify issue:<br>
> > > > > > <a href="https://github.com/kanaka/noVNC/issues/86" target="_blank">https://github.com/kanaka/noVNC/issues/86</a><br>
> > > > > > <a href="https://github.com/kanaka/websockify/issues/22#issuecomment-3263065" target="_blank">https://github.com/kanaka/websockify/issues/22#issuecomment-3263065</a><br>
> > > > > > <a href="https://github.com/kanaka/noVNC/issues/177" target="_blank">https://github.com/kanaka/noVNC/issues/177</a><br>
> > > > > ><br>
> > > > > > In any event I got both Chrome and Firefox working by manually<br>
> > > browsing<br>
> > > > > to:<br>
> > > > > > <a href="https://ENGINEFQDN:6100" target="_blank">https://ENGINEFQDN:6100</a> and accepting the self signed cert<br>
> > > > ><br>
> > > > > This is because your browser does not support the CA.<br>
> > > > > Please go to:<br>
> > > > ><br>
> > > > > <a href="http://engine/ca.crt" target="_blank">http://engine/ca.crt</a><br>
> > > > ><br>
> > > > > And install that certificate as trusted, remove the explicit trust<br>
> > > > > you<br>
> > > > > have added, and try again.<br>
> > > > ><br>
> > > > > ><br>
> > > > > > Not pretty but it worked.<br>
> > > > > ><br>
> > > > > > - DHC<br>
> > > > > ><br>
> > > > > ><br>
> > > > > > On Thu, Aug 1, 2013 at 2:08 PM, Alon Bar-Lev <<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>><br>
> > > wrote:<br>
> > > > > ><br>
> > > > > > ><br>
> > > > > > ><br>
> > > > > > > ----- Original Message -----<br>
> > > > > > > > From: "Dead Horse" <<a href="mailto:deadhorseconsulting@gmail.com">deadhorseconsulting@gmail.com</a>><br>
> > > > > > > > To: "Alon Bar-Lev" <<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>><br>
> > > > > > > > Cc: "users" <<a href="mailto:users@ovirt.org">users@ovirt.org</a>><br>
> > > > > > > > Sent: Thursday, August 1, 2013 9:59:14 PM<br>
> > > > > > > > Subject: Re: [Users] Questions on ovirt 3.3 browser based<br>
> > > spice/novnc<br>
> > > > > > > working<br>
> > > > > > > ><br>
> > > > > > > > That did the trick for getting the websocket proxy configured (<br>
> > > > > > > > i<br>
> > > > > backed<br>
> > > > > > > > out all my changes prior to running engine-setup). I do notice<br>
> > > that<br>
> > > > > it<br>
> > > > > > > > still seems to leave the ovirt-websocket-proxy.conf in it's<br>
> > > default<br>
> > > > > state<br>
> > > > > > > > and makes no dedications to it. Instead it generated<br>
> > > > > > > > /etc/ovirt-engine/ovirt-websocket-proxy.conf.d/10-setup.conf<br>
> > > > > > > ><br>
> > > > > > > > I also noted engine setup generated:<br>
> > > > > > > > /etc/pki/ovirt-engine/certs/websocket-proxy.cer<br>
> > > > > > > > /etc/pki/ovirt-engine/keys/websocket-proxy.p12<br>
> > > > > > > > /etc/pki/ovirt-engine/keys/websocket-proxy.key.nopass<br>
> > > > > > > > /etc/pki/ovirt-engine/requests/websocket-proxy.req<br>
> > > > > > > ><br>
> > > > > > > > None the less still neither spice nor novnc will connect. I<br>
> > > > > > > > tried<br>
> > > > > > > changing<br>
> > > > > > > > Engine:6100 to EngineIP:6100 so that IP would be used instead.<br>
> > > > > However<br>
> > > > > > > > using either the FQDN or IP still yielded the same results.<br>
> > > > > > ><br>
> > > > > > > You should not touch anything... all should be configured...<br>
> > > > > > > Make sure your browser trust the *CA* of the engine and not the<br>
> > > engine<br>
> > > > > > > certificate directly.<br>
> > > > > > > And try to open vnc console via webadmin.<br>
> > > > > > ><br>
> > > > > > > > There was nothing interesting in the logs either. I do notice<br>
> > > that<br>
> > > > > whilst<br>
> > > > > > > > the websocket-proxy service is running I never see an<br>
> > > > > > > > websockify<br>
> > > > > > > processes<br>
> > > > > > > > but instead in /var/log/messages I see:<br>
> > > > > > > > Aug 1 13:44:10 ovirtfoo ovirt-websocket-proxy.py[435]: 11:<br>
> > > handler<br>
> > > > > > > > exception: [Errno 1] _ssl.c:1359: error:14094418:SSL<br>
> > > > > > > > routines:SSL3_READ_BYTES:tlsv1 alert unknown ca<br>
> > > > > > > ><br>
> > > > > > > > Thus I changed SSL_ONLY=True to SSL_ONLY=False in<br>
> > > > > > > > /etc/ovirt-engine/ovirt-websocket-proxy.conf.d/10-setup.conf<br>
> > > > > > > > and<br>
> > > > > > > restarted<br>
> > > > > > > > engine and websocket-proxy<br>
> > > > > > > > No dice it still generated the same error as above during an<br>
> > > > > attempted<br>
> > > > > > > > connection to /var/log/messages<br>
> > > > > > > ><br>
> > > > > > > > I also not the following error message at VM power off (albeit<br>
> > > > > > > > I<br>
> > > am<br>
> > > > > > > > guessing it has nothing to do with this issue):<br>
> > > > > > > > 2013-08-01 13:41:03,742 ERROR<br>
> > > > > > > > [org.ovirt.engine.core.vdsbroker.DestroyVmVDSCommand]<br>
> > > > > (pool-6-thread-50)<br>
> > > > > > > > [304efb3e] VDS::destroy Failed destroying vm<br>
> > > > > > > > fec3260c-871a-4fbe-a006-9eee4fbfbbcc in vds =<br>
> > > > > > > > 5713e5c8-6252-4bce-a3f6-bbd8e1e6eb57 : ovirtnodefoo, error =<br>
> > > > > > > > org.ovirt.engine.core.vdsbroker.vdsbroker.VDSErrorException:<br>
> > > > > > > > VDSGenericException: VDSErrorException: Failed to DestroyVDS,<br>
> > > error =<br>
> > > > > > > > Unexpected exception<br>
> > > > > > > ><br>
> > > > > > > > - DHC<br>
> > > > > > > ><br>
> > > > > > > ><br>
> > > > > > > > On Thu, Aug 1, 2013 at 1:07 PM, Alon Bar-Lev<br>
> > > > > > > > <<a href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>><br>
> > > > > wrote:<br>
> > > > > > > ><br>
> > > > > > > > > If you install the proxy on the engine machine you just need:<br>
> > > > > > > > ><br>
> > > > > > > > > # yum install ovirt-engine-websocket-proxy<br>
> > > > > > > > > # engine-setup<br>
> > > > > > > > ><br>
> > > > > > > > > then answer yes when prompt if you like to configure<br>
> > > > > > > > > websocket<br>
> > > > > proxy.<br>
> > > > > > > > ><br>
> > > > > > > > > you can execute engine-setup again even if you already<br>
> > > installed.<br>
> > > > > > > > ><br>
> > > > > > > > > ----- Original Message -----<br>
> > > > > > > > > > From: "Dead Horse" <<a href="mailto:deadhorseconsulting@gmail.com">deadhorseconsulting@gmail.com</a>><br>
> > > > > > > > > > To: "<<a href="mailto:users@ovirt.org">users@ovirt.org</a>>" <<a href="mailto:users@ovirt.org">users@ovirt.org</a>><br>
> > > > > > > > > > Sent: Thursday, August 1, 2013 9:01:47 PM<br>
> > > > > > > > > > Subject: [Users] Questions on ovirt 3.3 browser based<br>
> > > spice/novnc<br>
> > > > > > > working<br>
> > > > > > > > > ><br>
> > > > > > > > > > After Referencing:<br>
> > > > > > > > > > <a href="http://www.ovirt.org/Features/noVNC_console" target="_blank">http://www.ovirt.org/Features/noVNC_console</a><br>
> > > > > > > > > > <a href="http://www.ovirt.org/Features/SpiceHTML5" target="_blank">http://www.ovirt.org/Features/SpiceHTML5</a><br>
> > > > > > > > > ><br>
> > > > > > > > > > and looking at some of the related engine code.<br>
> > > > > > > > > ><br>
> > > > > > > > > > I am still attempting to get the spice/novnc browser based<br>
> > > > > consoles<br>
> > > > > > > to<br>
> > > > > > > > > work.<br>
> > > > > > > > > ><br>
> > > > > > > > > > I am working from a build from master yesterday I used to<br>
> > > upgrade<br>
> > > > > > > over a<br>
> > > > > > > > > > previous 3.3 master build from about a month back.<br>
> > > > > > > > > ><br>
> > > > > > > > > > VDSM version on host is 4.12.0 built minutes ago.<br>
> > > > > > > > > ><br>
> > > > > > > > > > I have installed and configured the websocket proxy like<br>
> > > > > > > > > > so:<br>
> > > > > > > > > ><br>
> > > > > > > > > > Set WebSocketProxy to engine ENGINEIP port 6100<br>
> > > > > > > > > > engine-config -s WebSocketProxy=ENGINEIP:6100<br>
> > > > > > > > > ><br>
> > > > > > > > > > /usr/share/ovirt-engine/bin/pki-enroll-pkcs12.sh<br>
> > > > > > > --name=websocket-proxy<br>
> > > > > > > > > > --password=install --subject="/C=US/O=DHC/CN=ENGINEFQDN"<br>
> > > > > > > > > ><br>
> > > > > > > > > > This generates:<br>
> > > > > > > > > > /etc/pki/ovirt-engine/keys/websocket-proxy.p12<br>
> > > > > > > > > > /etc/pki/ovirt-engine/certs/websocket-proxy.cer<br>
> > > > > > > > > > /etc/pki/ovirt-engine/requests/websocket-proxy.req<br>
> > > > > > > > > ><br>
> > > > > > > > > > However it does not generate the key that websockify wants<br>
> > > so we<br>
> > > > > do:<br>
> > > > > > > > > > openssl pkcs12 -in websocket-proxy.p12 -nocerts -nodes -out<br>
> > > > > > > > > > /etc/pki/ovirt-engine/keys/websocket-proxy.key<br>
> > > > > > > > > ><br>
> > > > > > > > > > The configuration of ovirt-websocket-proxy:<br>
> > > > > > > > > > PROXY_HOST=*<br>
> > > > > > > > > > PROXY_PORT=6100<br>
> > > > > > > > > > SOURCE_IS_IPV6=False<br>
> > > > > > > > > ><br>
> > > SSL_CERTIFICATE=/etc/pki/ovirt-engine/certs/websocket-proxy.cer<br>
> > > > > > > > > > SSL_KEY=/etc/pki/ovirt-engine/keys/websocket-proxy.key<br>
> > > > > > > > > > FORCE_DATA_VERIFICATION=False<br>
> > > > > > > > > ><br>
> > > CERT_FOR_DATA_VERIFICATION=/etc/pki/ovirt-engine/certs/engine.cer<br>
> > > > > > > > > > SSL_ONLY=True<br>
> > > > > > > > > > TRACE_ENABLE=False<br>
> > > > > > > > > > TRACE_FILE=<br>
> > > > > > > > > > ENGINE_USR="/usr/share/ovirt-engine"<br>
> > > > > > > > > ><br>
> > > > > > > > > > Install spice-html5<br>
> > > > > > > > > > git clone<br>
> > > > > <a href="http://anongit.freedesktop.org/git/spice/spice-html5.git" target="_blank">http://anongit.freedesktop.org/git/spice/spice-html5.git</a><br>
> > > > > > > > > > mv spice-html5 /usr/share<br>
> > > > > > > > > ><br>
> > > > > > > > > > Test spice:<br>
> > > > > > > > > > In Webadmin UI we set create a VM, set display as spice,<br>
> > > start it<br>
> > > > > > > and set<br>
> > > > > > > > > > it's console to spice-html5.<br>
> > > > > > > > > > Result spice-html client opens in a new tab but does not<br>
> > > connect.<br>
> > > > > > > > > ><br>
> > > > > > > > > > From engine.log:<br>
> > > > > > > > > > 2013-08-01 12:49:52,352 INFO<br>
> > > > > > > > > [org.ovirt.engine.core.bll.SetVmTicketCommand]<br>
> > > > > > > > > > (ajp--127.0.0.1-8702-9) Running command: SetVmTicketCommand<br>
> > > > > internal:<br>
> > > > > > > > > false.<br>
> > > > > > > > > > Entities affected : ID:<br>
> > > > > > > > > > fec3260c-871a-4fbe-a006-9eee4fbfbbcc<br>
> > > > > Type: VM<br>
> > > > > > > > > > 2013-08-01 12:49:52,371 INFO<br>
> > > > > > > > > ><br>
> > > [org.ovirt.engine.core.vdsbroker.vdsbroker.SetVmTicketVDSCommand]<br>
> > > > > > > > > > (ajp--127.0.0.1-8702-9) START,<br>
> > > SetVmTicketVDSCommand(HostName =<br>
> > > > > > > > > > ovirtnodefoo, HostId =<br>
> > > > > > > > > > 5713e5c8-6252-4bce-a3f6-bbd8e1e6eb57,<br>
> > > > > > > > > > vmId=fec3260c-871a-4fbe-a006-9eee4fbfbbcc,<br>
> > > ticket=TKfzUQJLLrUI,<br>
> > > > > > > > > > validTime=120,m userName=admin@internal,<br>
> > > > > > > > > > userId=fdfc627c-d875-11e0-90f0-83df133b58cc), log id:<br>
> > > 5d258049<br>
> > > > > > > > > > 2013-08-01 12:49:52,445 INFO<br>
> > > > > > > > > ><br>
> > > [org.ovirt.engine.core.vdsbroker.vdsbroker.SetVmTicketVDSCommand]<br>
> > > > > > > > > > (ajp--127.0.0.1-8702-9) FINISH, SetVmTicketVDSCommand, log<br>
> > > id:<br>
> > > > > > > 5d258049<br>
> > > > > > > > > ><br>
> > > > > > > > > > Test novnc:<br>
> > > > > > > > > > In Webadmin UI we set create a VM, set display as VNC,<br>
> > > > > > > > > > start<br>
> > > it<br>
> > > > > and<br>
> > > > > > > set<br>
> > > > > > > > > it's<br>
> > > > > > > > > > console to novnc.<br>
> > > > > > > > > > Result novnc client opens in a new tab but does not<br>
> > > > > > > > > > connect,<br>
> > > but<br>
> > > > > does<br>
> > > > > > > > > display<br>
> > > > > > > > > > error: "Server disconnected (code: 1006)<br>
> > > > > > > > > ><br>
> > > > > > > > > > From engine.log:<br>
> > > > > > > > > > 2013-08-01 12:50:44,800 INFO<br>
> > > > > > > > > [org.ovirt.engine.core.bll.SetVmTicketCommand]<br>
> > > > > > > > > > (ajp--127.0.0.1-8702-9) Running command: SetVmTicketCommand<br>
> > > > > internal:<br>
> > > > > > > > > false.<br>
> > > > > > > > > > Entities affected : ID:<br>
> > > > > > > > > > fec3260c-871a-4fbe-a006-9eee4fbfbbcc<br>
> > > > > Type: VM<br>
> > > > > > > > > > 2013-08-01 12:50:44,833 INFO<br>
> > > > > > > > > ><br>
> > > [org.ovirt.engine.core.vdsbroker.vdsbroker.SetVmTicketVDSCommand]<br>
> > > > > > > > > > (ajp--127.0.0.1-8702-9) START,<br>
> > > SetVmTicketVDSCommand(HostName =<br>
> > > > > > > > > > ovirtnodefoo, HostId =<br>
> > > > > > > > > > 5713e5c8-6252-4bce-a3f6-bbd8e1e6eb57,<br>
> > > > > > > > > > vmId=fec3260c-871a-4fbe-a006-9eee4fbfbbcc,<br>
> > > ticket=IPWOWh6U9erd,<br>
> > > > > > > > > > validTime=120,m userName=admin@internal,<br>
> > > > > > > > > > userId=fdfc627c-d875-11e0-90f0-83df133b58cc), log id:<br>
> > > > > > > > > > bff6161<br>
> > > > > > > > > > 2013-08-01 12:50:44,917 INFO<br>
> > > > > > > > > ><br>
> > > [org.ovirt.engine.core.vdsbroker.vdsbroker.SetVmTicketVDSCommand]<br>
> > > > > > > > > > (ajp--127.0.0.1-8702-9) FINISH, SetVmTicketVDSCommand, log<br>
> > > id:<br>
> > > > > > > bff6161<br>
> > > > > > > > > ><br>
> > > > > > > > > > I verified connection of both the spice/vnc console<br>
> > > > > > > > > > directly<br>
> > > at<br>
> > > > > the<br>
> > > > > > > host<br>
> > > > > > > > > > level with a quick connect via virt-viewer.<br>
> > > > > > > > > ><br>
> > > > > > > > > > A quick scan with nmap of engine and host to verify sockets<br>
> > > are<br>
> > > > > open:<br>
> > > > > > > > > ><br>
> > > > > > > > > > Nmap scan report for engine<br>
> > > > > > > > > > Host is up (0.0042s latency).<br>
> > > > > > > > > > Not shown: 995 closed ports<br>
> > > > > > > > > > PORT STATE SERVICE<br>
> > > > > > > > > > 22/tcp open ssh<br>
> > > > > > > > > > 80/tcp open http<br>
> > > > > > > > > > 111/tcp open rpcbind<br>
> > > > > > > > > > 443/tcp open https<br>
> > > > > > > > > > 6100/tcp open synchronet-db<br>
> > > > > > > > > ><br>
> > > > > > > > > > Nmap scan report for host<br>
> > > > > > > > > > Host is up (0.0045s latency).<br>
> > > > > > > > > > Not shown: 997 closed ports<br>
> > > > > > > > > > PORT STATE SERVICE<br>
> > > > > > > > > > 22/tcp open ssh<br>
> > > > > > > > > > 111/tcp open rpcbind<br>
> > > > > > > > > > 5900/tcp open vnc<br>
> > > > > > > > > ><br>
> > > > > > > > > > For grins I stopped the websocket proxy and manually<br>
> > > > > > > > > > started<br>
> > > a<br>
> > > > > > > websockify<br>
> > > > > > > > > > like so:<br>
> > > > > > > > > > websockify <a href="http://3.57.111.11:6100" target="_blank">3.57.111.11:6100</a> <a href="http://3.57.111.12:5900" target="_blank">3.57.111.12:5900</a><br>
> > > > > > > > > > --cert=/etc/pki/ovirt-engine/certs/websocket-proxy.cer<br>
> > > > > > > > > > --key=/etc/pki/ovirt-engine/keys/websocket-proxy.key<br>
> > > > > > > > > ><br>
> > > > > > > > > > WARNING: no 'numpy' module, HyBi protocol is slower or<br>
> > > disabled<br>
> > > > > > > > > > WebSocket server settings:<br>
> > > > > > > > > > - Listen on ENGINEIP:6100<br>
> > > > > > > > > > - Flash security policy server<br>
> > > > > > > > > > - SSL/TLS support<br>
> > > > > > > > > > - proxying from ENGINEIP:6100 to HOSTIP:5900<br>
> > > > > > > > > ><br>
> > > > > > > > > > Attempting another connection via<br>
> > > > > > > > > ><br>
> > > > > > ><br>
> > > > ><br>
> > > <a href="https://ENGINEFQDN//ovirt-engine-novnc-main.html?host=ENGINEIP&port=6100" target="_blank">https://ENGINEFQDN//ovirt-engine-novnc-main.html?host=ENGINEIP&port=6100</a><br>
> > > > > > > > > > results in:<br>
> > > > > > > > > ><br>
> > > > > > > > > > 1: handler exception: [Errno 1] _ssl.c:1359:<br>
> > > error:14094418:SSL<br>
> > > > > > > > > > routines:SSL3_READ_BYTES:tlsv1 alert unknown ca<br>
> > > > > > > > > ><br>
> > > > > > > > > ><br>
> > > > > > > > > > I should also note in case it matters that the<br>
> > > SSLEnabled=false,<br>
> > > > > and<br>
> > > > > > > > > > EnableSpiceRootCertificateValidation are both set as false<br>
> > > are<br>
> > > > > set<br>
> > > > > > > in my<br>
> > > > > > > > > > engine options.<br>
> > > > > > > > > ><br>
> > > > > > > > > > Am I doing something wrong here, I don't see any reason<br>
> > > > > > > > > > this<br>
> > > > > should<br>
> > > > > > > not<br>
> > > > > > > > > work?<br>
> > > > > > > > > ><br>
> > > > > > > > > > - DHC<br>
> > > > > > > > > ><br>
> > > > > > > > > > _______________________________________________<br>
> > > > > > > > > > Users mailing list<br>
> > > > > > > > > > <a href="mailto:Users@ovirt.org">Users@ovirt.org</a><br>
> > > > > > > > > > <a href="http://lists.ovirt.org/mailman/listinfo/users" target="_blank">http://lists.ovirt.org/mailman/listinfo/users</a><br>
> > > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > ><br>
> > > > > > ><br>
> > > > > ><br>
> > > > ><br>
> > > ><br>
> > ><br>
> ><br>
><br>
</div></div></blockquote></div><br></div>