Once upon a time, John Florian <jflorian(a)doubledog.org> said:
Just to follow up on this Chris, I have my puppet drop my CA cert in
/etc/pki/ca-trust/source/anchors/, my self-signed cert
in/etc/pki/ovirt-engine/certs/ and my key in
/etc/pki/ovirt-engine/keys. I also manage
/etc/ovirt-engine/engine.conf.d/99-custom-truststore.conf to have:
ENGINE_HTTPS_PKI_TRUST_STORE="/etc/pki/java/cacerts"
ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD=""
I believe this gives me everything you seek.
That works to get the core engine UI using a new cert (that and a little
more are in the Red Hat URL in my original message). It doesn't handle
the imageio-proxy however.
--
Chris Adams <cma(a)cmadams.net>