Hi,
what are 'source' and 'target' ovirt engine versions?
Indeed, update key&certificate on old engine seems as good way forward
It seems that
https://myhomelab.gr/linux/2020/01/20/replacing_ovirt_ssl.html
and/or
https://rhv.bradmin.org/ovirt-engine/docs/Upgrade_Guide/Replacing_SHA-1_C...
will solve it for you.
BR,
Konstantin
Am 12.05.23, 12:50 schrieb "Frank Wall" <fw(a)moov.de
<mailto:fw@moov.de>>:
Hi,
I was trying to restore a oVirt Engine Backup into a new Hosted Engine
appliance (as part of an upgrade), but this failed with the following
error:
--== PKI CONFIGURATION ==--
[WARNING] Failed to read or parse
'/etc/pki/ovirt-engine/keys/engine.p12'
Perhaps it was changed since last Setup.
Error was:
Error outputting keys and certificates
80EBCC44677F0000:error:0308010C:digital envelope
routines:inner_evp_generic_fetch:unsupported:crypto/evp/evp_fetch.c:373:Global
default library context, Algorithm (RC2-40-CBC : 0)
It looks like this is related to openssl requiring legacy mode
to use the old Engine cert/key.
Is there any way to workaround this? Or would it be possible
to repackage the existing PCKS#12 file with new encryption (on
the old Engine)?
Regards
- Frank
_______________________________________________
Users mailing list -- users(a)ovirt.org <mailto:users@ovirt.org>
To unsubscribe send an email to users-leave(a)ovirt.org
<mailto:users-leave@ovirt.org>
Privacy Statement:
https://www.ovirt.org/privacy-policy.html
<
https://www.ovirt.org/privacy-policy.html>
oVirt Code of Conduct:
https://www.ovirt.org/community/about/community-guidelines/
<
https://www.ovirt.org/community/about/community-guidelines/>
List Archives:
https://lists.ovirt.org/archives/list/users@ovirt.org
<mailto:users@ovirt.org>/message/YI647H7YWRHJKDXNP4DJDEHU4ZWKCHY2/