This is a multi-part message in MIME format.
--------------030502060003060901030103
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
On 08/14/2014 03:07 PM, Punit Dambiwal wrote:
Hi All,
Is there any one can help me to solve this issue..
Look for details at
http://www.ovirt.org/Features/PKI
(User--SSL-->apache--AJP-->ovirt-engine), that may help you.
Thanks,
Punit
On Wed, Aug 13, 2014 at 9:53 AM, Punit Dambiwal <hypunit(a)gmail.com
<mailto:hypunit@gmail.com>> wrote:
Hi All,
I have one question regarding the SSL settings in Ovirt....let me
explain my environment first :-
1. Ovirt engine :-
mgmt.3linux.com <
http://mgmt.3linux.com>
2. Standalone websocket proxy :-
web-proxy.3linux.com
<
http://web-proxy.3linux.com>
3. Our Own Portal :-
portal.3linux.com <
http://portal.3linux.com>
We have the above architecture...we fetch the VM console from the
websocket proxy to our own portal through API....because still we
are using selfsigned certificate...we need to trust the
certificate every time,whenever we open the VM console...
(https://<web-proxy.3linux.com
<
http://web-proxy.3linux.com>>:<port>)
When we initiate the VM console through our own web portal the url
(
https://portal.3linux.com/content/ovirt/noVNC/vm-console.php?id=6e0caf73-...
we accept the SSL certificate with https://<web-proxy.3linux.com
<
http://web-proxy.3linux.com>>:<port> ....then it will open as
expected but if we didn't accept the certificate manually...then
it through failed to connect:1006 error...
We don't want that every time end user will accept the certificate
manually...as our link to open VM console is different then
webproxy....
Now we want to replace the self signed certificate with valid
SSL....can any one tell me where we need to put the certificates
and how to generate the CSR for them and how many SSL we need to
purchase to make this thing workable without accepting the
certificate everytime....
Thanks,
Punit
--------------030502060003060901030103
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit
<html>
<head>
<meta content="text/html; charset=UTF-8"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<br>
<div class="moz-cite-prefix">On 08/14/2014 03:07 PM, Punit Dambiwal
wrote:<br>
</div>
<blockquote
cite="mid:CAGZcrBnMU3abABXFFUpDKiXmYQyopiTaAcJyjcCmU6+HRh_PoQ@mail.gmail.com"
type="cite">
<div dir="ltr">Hi All,
<div><br>
</div>
<div>Is there any one can help me to solve this issue..</div>
</div>
</blockquote>
<br>
<br>
Look for details at <a class="moz-txt-link-freetext"
href="http://www.ovirt.org/Features/PKI">http://www.ovirt.or...
(User--SSL-->apache--AJP-->ovirt-engine), that may help you.<br>
<br>
<blockquote
cite="mid:CAGZcrBnMU3abABXFFUpDKiXmYQyopiTaAcJyjcCmU6+HRh_PoQ@mail.gmail.com"
type="cite">
<div dir="ltr">
<div><br>
</div>
<div>Thanks,</div>
<div>Punit</div>
</div>
<div class="gmail_extra"><br>
<br>
<div class="gmail_quote">On Wed, Aug 13, 2014 at 9:53 AM, Punit
Dambiwal <span dir="ltr"><<a
moz-do-not-send="true"
href="mailto:hypunit@gmail.com"
target="_blank">hypunit(a)gmail.com</a>&gt;</span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="ltr">Hi All,
<div><br>
</div>
<div>I have one question regarding the SSL settings in
Ovirt....let me explain my environment first :-</div>
<div><br>
</div>
<div>1. Ovirt engine :- <a moz-do-not-send="true"
href="http://mgmt.3linux.com"
target="_blank">mgmt.3linux.com</a></div>
<div>2. Standalone websocket proxy :- <a
moz-do-not-send="true"
href="http://web-proxy.3linux.com"
target="_blank">web-proxy.3linux.com</a></div>
<div>3. Our Own Portal :- <a moz-do-not-send="true"
href="http://portal.3linux.com"
target="_blank">portal.3linux.com</a></div>
<div><br>
</div>
<div>We have the above architecture...we fetch the VM
console from the websocket proxy to our own portal
through API....because still we are using selfsigned
certificate...we need to trust the certificate every
time,whenever we open the VM console... (<a
class="moz-txt-link-freetext"
href="https://">https://</a><<a
moz-do-not-send="true"
href="http://web-proxy.3linux.com"
target="_blank">web-proxy.3linux.com</a>>:<port>)</div>
<div><br>
</div>
<div>When we initiate the VM console through our own web
portal the url (<a moz-do-not-send="true"
href="https://portal.3linux.com/content/ovirt/noVNC/vm-console.php?i...
target="_blank">https://portal.3linux.com/content/ovirt/noVN...
we accept the SSL certificate with <a
class="moz-txt-link-freetext"
href="https://">https://</a><<a
moz-do-not-send="true"
href="http://web-proxy.3linux.com"
target="_blank">web-proxy.3linux.com</a>>:<port>
....then it will open as expected but if we didn't
accept the certificate manually...then it through failed
to connect:1006 error...</div>
<div><br>
</div>
<div>We don't want that every time end user will accept
the certificate manually...as our link to open VM
console is different then webproxy....</div>
<div><br>
</div>
<div>Now we want to replace the self signed certificate
with valid SSL....can any one tell me where we need to
put the certificates and how to generate the CSR for
them and how many SSL we need to purchase to make this
thing workable without accepting the certificate
everytime....</div>
<div><br>
</div>
<div>Thanks,</div>
<div>Punit </div>
</div>
</blockquote>
</div>
<br>
</div>
</blockquote>
<br>
</body>
</html>
--------------030502060003060901030103--