<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Wed, Aug 24, 2016 at 9:57 PM, Ralf Schenk <span dir="ltr">&lt;<a href="mailto:rs@databay.de" target="_blank">rs@databay.de</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
  

    
  
  <div bgcolor="#FFFFFF" text="#000000">
    <p>Hello List,<br>
    </p>
    <p>After upgrading ovirt-hosted-engine setup failed with &quot;Failed to
      start service &#39;ovirt-imageio-proxy&#39;&quot;.</p>
    <p>If try to start it manually via <br>
    </p>
    journalctl -xe shows following error:<br>
    Aug 24 20:51:10 engine.mydomain.local ovirt-imageio-proxy[7635]:
    self._secure_server(config, server)<br>
    Aug 24 20:51:10 engine.mydomain.local ovirt-imageio-proxy[7635]:
    File
    &quot;/usr/lib/python2.7/site-<wbr>packages/ovirt_imageio_proxy/<wbr>server.py&quot;,
    line<br>
    Aug 24 20:51:10 engine.mydomain.local ovirt-imageio-proxy[7635]:
    server_side=True)<br>
    Aug 24 20:51:10 engine.mydomain.local ovirt-imageio-proxy[7635]:
    File &quot;/usr/lib64/python2.7/ssl.py&quot;, line 913, in wrap_socket<br>
    Aug 24 20:51:10 engine.mydomain.local ovirt-imageio-proxy[7635]:
    ciphers=ciphers)<br>
    Aug 24 20:51:10 engine.mydomain.local ovirt-imageio-proxy[7635]:
    File &quot;/usr/lib64/python2.7/ssl.py&quot;, line 526, in __init__<br>
    Aug 24 20:51:10 engine.mydomain.local ovirt-imageio-proxy[7635]:
    self._context.load_cert_chain(<wbr>certfile, keyfile)<br>
    Aug 24 20:51:10 engine.mydomain.local ovirt-imageio-proxy[7635]:
    IOError: [Errno 2] No such file or directory<br>
    Aug 24 20:51:10 engine.mydomain.local systemd[1]:
    ovirt-imageio-proxy.service: main process exited, code=exited,
    status=1/FAILURE<br>
    Aug 24 20:51:10 engine.mydomain.local systemd[1]: Failed to start
    oVirt ImageIO Proxy.<br>
    <br>
    Config (/etc/ovirt-imageio-proxy/<wbr>ovirt-imageio-proxy.conf) points to
    a non-existing cert<br>
    /etc/pki/ovirt-engine/certs/<wbr>imageio-proxy.cer<br>
    and nonexisting key:<br>
    /etc/pki/ovirt-engine/keys/<wbr>imageio-proxy.key.nopass<br></div></blockquote><div><br></div><div>Right, will be fixed in 4.0.3:<br><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=1365451">https://bugzilla.redhat.com/show_bug.cgi?id=1365451</a><br></div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div bgcolor="#FFFFFF" text="#000000">
    <br>
    How to generate a correct cert and key for correct startup ?<br></div></blockquote><div><br></div><div>There is no simple single one-liner to do that for now.<br></div><div><br></div><div>Search for &quot;pki-enroll-pkcs12.sh&quot; for examples if you really want to.<br></div><div><br></div><div>You can copy e.g. websocket-proxy key/cert.<br><br></div><div>You can use the 4.0 nightly repo - bugs in MODIFIED are already fixed there:<br><br><a href="http://www.ovirt.org/develop/dev-process/install-nightly-snapshot/">http://www.ovirt.org/develop/dev-process/install-nightly-snapshot/</a><br></div><div><br></div><div>You can answer &#39;no&#39; to &#39;configure image i/o proxy?&#39;, if you don&#39;t need it.<br></div><div>It&#39;s only needed for the new image uploader:<br><br><a href="http://www.ovirt.org/develop/release-management/features/storage/image-upload/">http://www.ovirt.org/develop/release-management/features/storage/image-upload/</a><br></div><div><br></div><div>Or you can wait for 4.0.3.<br><br></div><div>Best,<br></div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div bgcolor="#FFFFFF" text="#000000">
    <br>
    Bye<br>
    <div>-- <br>
      <p>
      </p>
      <table border="0" cellpadding="0" cellspacing="0">
        <tbody>
          <tr>
            <td colspan="3"><img src="cid:part1.15F71E8B.067645E0@databay.de" height="30" width="151" border="0"></td>
          </tr>
          <tr>
            <td valign="top"> <font face="Verdana, Arial, sans-serif" size="-1"><br>
                <b>Ralf Schenk</b><br>
                fon <a href="tel:%2B49%20%280%29%2024%2005%20%2F%2040%2083%2070" value="+492405408370" target="_blank">+49 (0) 24 05 / 40 83 70</a><br>
                fax <a href="tel:%2B49%20%280%29%2024%2005%20%2F%2040%2083%20759" value="+4924054083759" target="_blank">+49 (0) 24 05 / 40 83 759</a><br>
                mail <a href="mailto:rs@databay.de" target="_blank"><font color="#FF0000"><b>rs@databay.de</b></font></a><br>
              </font> </td>
            <td width="30"> </td>
            <td valign="top"> <font face="Verdana, Arial, sans-serif" size="-1"><br>
                <b>Databay AG</b><br>
                Jens-Otto-Krag-Straße 11<br>
                D-52146 Würselen<br>
                <a href="http://www.databay.de" target="_blank"><font color="#FF0000"><b>www.databay.de</b></font></a>
              </font> </td>
          </tr>
          <tr>
            <td colspan="3" valign="top"> <font face="Verdana, Arial,
                sans-serif" size="1"><br>
                Sitz/Amtsgericht Aachen • HRB:8437 • USt-IdNr.: DE
                210844202<br>
                Vorstand: Ralf Schenk, Dipl.-Ing. Jens Conze, Aresch
                Yavari, Dipl.-Kfm. Philipp Hermanns<br>
                Aufsichtsratsvorsitzender: Klaus Scholzen (RA) </font>
            </td>
          </tr>
        </tbody>
      </table>
      <hr color="#000000" size="1" noshade width="100%">
    </div>
  </div>

<br>______________________________<wbr>_________________<br>
Users mailing list<br>
<a href="mailto:Users@ovirt.org">Users@ovirt.org</a><br>
<a href="http://lists.ovirt.org/mailman/listinfo/users" rel="noreferrer" target="_blank">http://lists.ovirt.org/<wbr>mailman/listinfo/users</a><br>
<br></blockquote></div><br><br clear="all"><br>-- <br><div class="gmail_signature" data-smartmail="gmail_signature">Didi<br></div>
</div></div>