<html><body><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: #000000"><div>Hi,<br></div><div><br></div><div><span id="zwchr" data-marker="__DIVIDER__">----- Le 1 Sep 15, à 9:43, Sandro Bonazzola &lt;sbonazzo@redhat.com&gt; a écrit :<br></span></div><div data-marker="__QUOTED_TEXT__"><blockquote style="border-left: 2px solid #1010FF; margin-left: 5px; padding-left: 5px; color: #000; font-weight: normal; font-style: normal; text-decoration: none; font-family: Helvetica,Arial,sans-serif; font-size: 12pt;" data-mce-style="border-left: 2px solid #1010FF; margin-left: 5px; padding-left: 5px; color: #000; font-weight: normal; font-style: normal; text-decoration: none; font-family: Helvetica,Arial,sans-serif; font-size: 12pt;"><div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Aug 31, 2015 at 6:08 PM, Alon Bar-Lev <span dir="ltr">&lt;<a href="mailto:alonbl@redhat.com" target="_blank" data-mce-href="mailto:alonbl@redhat.com">alonbl@redhat.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin: 0 0 0 .8ex; border-left: 1px #ccc solid; padding-left: 1ex;" data-mce-style="margin: 0 0 0 .8ex; border-left: 1px #ccc solid; padding-left: 1ex;"><span class=""><br> <br> ----- Original Message -----<br> &gt; From: "Baptiste Agasse" &lt;<a href="mailto:baptiste.agasse@lyra-network.com" target="_blank" data-mce-href="mailto:baptiste.agasse@lyra-network.com">baptiste.agasse@lyra-network.com</a>&gt;<br> &gt; To: "users" &lt;<a href="mailto:users@ovirt.org" target="_blank" data-mce-href="mailto:users@ovirt.org">users@ovirt.org</a>&gt;<br> &gt; Sent: Monday, August 31, 2015 6:54:28 PM<br> &gt; Subject: [ovirt-users] ovirt 3.5 engine web certificate<br> &gt;<br> &gt; Hi all,<br> &gt;<br> &gt; I've followed the procedure to replace self signed certificate to one issued<br> &gt; by our internal PKI to avoid security failure when users access to the webui<br> &gt; (<a href="https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Virtualization/3.5/html/Administration_Guide/appe-Red_Hat_Enterprise_Virtualization_and_SSL.html#Replacing_the_SSL_certificate_used_by_Red_Hat_Enterprise_Virtualization_Manager_to_identify_itself_to_users_connecting_over_https" rel="noreferrer" target="_blank" data-mce-href="https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Virtualization/3.5/html/Administration_Guide/appe-Red_Hat_Enterprise_Virtualization_and_SSL.html#Replacing_the_SSL_certificate_used_by_Red_Hat_Enterprise_Virtualization_Manager_to_identify_itself_to_users_connecting_over_https">https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Virtualization/3.5/html/Administration_Guide/appe-Red_Hat_Enterprise_Virtualization_and_SSL.html#Replacing_the_SSL_certificate_used_by_Red_Hat_Enterprise_Virtualization_Manager_to_identify_itself_to_users_connecting_over_https</a>).<br> &gt; The connection to the webui now works fine without any security warning (the<br> &gt; internal PKI CA is in the trusted CA of our clients OS). But on the other<br> &gt; hand, i've some troubles:<br> &gt;<br> &gt; * I've to specify the --ca-file option for ovirt-shell and<br> &gt; engine-iso-uploader (i didn't test the engine-image-upload command), it will<br> &gt; be nice if the documentation provide a way to replace this by default (or<br> &gt; use the trusted ca store of the OS ?). This is not a bug just some feedback<br> &gt; on the certificate change procedure that don't cover these side effects.<br> <br> </span>This is [1], probably you want to modify the configuration files of these tools at /etc so you will have proper defaults.<br><br> [1] <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1146710" rel="noreferrer" target="_blank" data-mce-href="https://bugzilla.redhat.com/show_bug.cgi?id=1146710">https://bugzilla.redhat.com/show_bug.cgi?id=1146710</a><br data-mce-bogus="1"></blockquote></div></div></div></blockquote><div><br></div><div>Thank you for this link.<br data-mce-bogus="1"></div><div><br data-mce-bogus="1"></div><blockquote style="border-left: 2px solid #1010FF; margin-left: 5px; padding-left: 5px; color: #000; font-weight: normal; font-style: normal; text-decoration: none; font-family: Helvetica,Arial,sans-serif; font-size: 12pt;" data-mce-style="border-left: 2px solid #1010FF; margin-left: 5px; padding-left: 5px; color: #000; font-weight: normal; font-style: normal; text-decoration: none; font-family: Helvetica,Arial,sans-serif; font-size: 12pt;"><div dir="ltr"><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin: 0 0 0 .8ex; border-left: 1px #ccc solid; padding-left: 1ex;" data-mce-style="margin: 0 0 0 .8ex; border-left: 1px #ccc solid; padding-left: 1ex;"><span class=""><br> &gt; * I can't add new ovirt-node anymore.<br> <br> </span>If ovirt-node was added using previous certificate it "Remembers" that certificate.<br> You can remove it from /etc/pki/vdsm/engine_web_ca.pem and try to register again.<br><br> &gt; * The ovirt-hosted-engine --deploy fails<br><span class="">&gt; on new nodes with an SSL error. To workaround this i've to modify the file<br> &gt; "/usr/lib/python2.7/site-packages/ovirtsdk/web/connection.py" around line<br> &gt; 233 to make an insecure connection to the engine and add the new node. I<br> &gt; didn't have tested to add a new node from the ovirt engine cli/webui but i<br> &gt; think it will be the same issue because the error occurs on the vdsm<br> &gt; activation that is common to the 'new hosted engine node' and 'new node'<br> &gt; deployment. I've seen <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1059952" rel="noreferrer" target="_blank" data-mce-href="https://bugzilla.redhat.com/show_bug.cgi?id=1059952">https://bugzilla.redhat.com/show_bug.cgi?id=1059952</a><br> &gt; but the workaround noted in the comment #8 didn't work for me.<br> <br> </span>CC sandro for this.<br></blockquote><br><div>Can you please share full sos report?</div></div></div></div></blockquote><div><br></div><div>The report is a little bit big (about 57MB) to be sent by mail, have you any procedure i can use to send it to you ?<br data-mce-bogus="1"></div><div><br data-mce-bogus="1"></div><blockquote style="border-left: 2px solid #1010FF; margin-left: 5px; padding-left: 5px; color: #000; font-weight: normal; font-style: normal; text-decoration: none; font-family: Helvetica,Arial,sans-serif; font-size: 12pt;" data-mce-style="border-left: 2px solid #1010FF; margin-left: 5px; padding-left: 5px; color: #000; font-weight: normal; font-style: normal; text-decoration: none; font-family: Helvetica,Arial,sans-serif; font-size: 12pt;"><div dir="ltr"><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin: 0 0 0 .8ex; border-left: 1px #ccc solid; padding-left: 1ex;" data-mce-style="margin: 0 0 0 .8ex; border-left: 1px #ccc solid; padding-left: 1ex;"><div class="HOEnZb"><div class="h5"><br> &gt;<br> &gt; Someone have more info on this issue or have the same problem ?<br> &gt;<br> &gt; This deployment is on ovirt 3.5.3, CentOS 7 (engine and nodes).<br> &gt;<br> &gt; Have a nice day.<br> &gt;<br> &gt; Regards.<br> &gt;<br> &gt; --<br> &gt; Baptiste<br> &gt; _______________________________________________<br> &gt; Users mailing list<br> &gt; <a href="mailto:Users@ovirt.org" target="_blank" data-mce-href="mailto:Users@ovirt.org">Users@ovirt.org</a><br> &gt; <a href="http://lists.ovirt.org/mailman/listinfo/users" rel="noreferrer" target="_blank" data-mce-href="http://lists.ovirt.org/mailman/listinfo/users">http://lists.ovirt.org/mailman/listinfo/users</a><br> &gt;<br></div></div></blockquote></div><br><br clear="all"><br>-- <br><div class="gmail_signature"><div dir="ltr"><div><div dir="ltr">Sandro Bonazzola<br>Better technology. Faster innovation. Powered by community collaboration.<br>See how it works at <a href="http://redhat.com" target="_blank" data-mce-href="http://redhat.com">redhat.com</a><br></div></div></div></div></div></div><br></blockquote></div><div><br></div><div data-marker="__SIG_POST__">-- <br></div><div>Baptiste</div><mytubeelement data="{&quot;bundle&quot;:{&quot;label_delimitor&quot;:&quot;:&quot;,&quot;percentage&quot;:&quot;%&quot;,&quot;smart_buffer&quot;:&quot;Smart Buffer&quot;,&quot;start_playing_when_buffered&quot;:&quot;Start playing when buffered&quot;,&quot;sound&quot;:&quot;Sound&quot;,&quot;desktop_notification&quot;:&quot;Desktop Notification&quot;,&quot;continuation_on_next_line&quot;:&quot;-&quot;,&quot;loop&quot;:&quot;Loop&quot;,&quot;only_notify&quot;:&quot;Only Notify&quot;,&quot;estimated_time&quot;:&quot;Estimated Time&quot;,&quot;global_preferences&quot;:&quot;Global Preferences&quot;,&quot;no_notification_supported_on_your_browser&quot;:&quot;No notification style supported on your browser version&quot;,&quot;video_buffered&quot;:&quot;Video Buffered&quot;,&quot;buffered&quot;:&quot;Buffered&quot;,&quot;hyphen&quot;:&quot;-&quot;,&quot;buffered_message&quot;:&quot;The video has been buffered as requested and is ready to play.&quot;,&quot;not_supported&quot;:&quot;Not Supported&quot;,&quot;on&quot;:&quot;On&quot;,&quot;off&quot;:&quot;Off&quot;,&quot;click_to_enable_for_this_site&quot;:&quot;Click to enable for this site&quot;,&quot;desktop_notification_denied&quot;:&quot;You have denied permission for desktop notification for this site&quot;,&quot;notification_status_delimitor&quot;:&quot;;&quot;,&quot;error&quot;:&quot;Error&quot;,&quot;adblock_interferance_message&quot;:&quot;Adblock (or similar extension) is known to interfere with SmartVideo. Please add this url to adblock whitelist.&quot;,&quot;calculating&quot;:&quot;Calculating&quot;,&quot;waiting&quot;:&quot;Waiting&quot;,&quot;will_start_buffering_when_initialized&quot;:&quot;Will start buffering when initialized&quot;,&quot;will_start_playing_when_initialized&quot;:&quot;Will start playing when initialized&quot;,&quot;completed&quot;:&quot;Completed&quot;,&quot;buffering_stalled&quot;:&quot;Buffering is stalled. Will stop.&quot;,&quot;stopped&quot;:&quot;Stopped&quot;,&quot;hr&quot;:&quot;Hr&quot;,&quot;min&quot;:&quot;Min&quot;,&quot;sec&quot;:&quot;Sec&quot;,&quot;any_moment&quot;:&quot;Any Moment&quot;,&quot;popup_donate_to&quot;:&quot;Donate to&quot;,&quot;extension_id&quot;:null},&quot;prefs&quot;:{&quot;desktopNotification&quot;:true,&quot;soundNotification&quot;:true,&quot;logLevel&quot;:0,&quot;enable&quot;:true,&quot;loop&quot;:false,&quot;hidePopup&quot;:false,&quot;autoPlay&quot;:false,&quot;autoBuffer&quot;:true,&quot;autoPlayOnBuffer&quot;:true,&quot;autoPlayOnBufferPercentage&quot;:42,&quot;autoPlayOnSmartBuffer&quot;:true,&quot;quality&quot;:&quot;hd720&quot;,&quot;fshd&quot;:false,&quot;onlyNotification&quot;:false,&quot;enableFullScreen&quot;:true,&quot;saveBandwidth&quot;:false,&quot;hideAnnotations&quot;:false,&quot;turnOffPagedBuffering&quot;:true}}" event="preferencesUpdated" id="myTubeRelayElementToPage"></mytubeelement><mytubeelement data="{&quot;loadBundle&quot;:true}" event="relayPrefs" id="myTubeRelayElementToTab"></mytubeelement></div></body></html>