Yes, that is the exact guide I followed.


I can now actually use vdsm-client on each host after cert swap but ovirt-engine still can't establish connection.


I had to manually generate the apache certs to get into the UI console at the beginning and that was successful.

Is there a specific cert that ovirt-engine uses for mTLS handshahe?



On 10/03/2023 07:54, Patrick Chiang wrote:
Hi,

Where do host certs need to be stored on the ovirt-engine side?

Did you try this link?
https://access.redhat.com/solutions/3532921
How to manually renew RHV host SSL certificate if expired?

You can register a Red Hat developer subscription (free) to access this link.

Patrick