This is a multi-part message in MIME format.
------=_NextPartTM-000-c9fbc65d-1b8a-45b7-96bc-aa2de25be96e
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Von: Alon Bar-Lev [alonbl(a)redhat.com]=0A=
Gesendet: Samstag, 11. Januar 2014 19:56=0A=
An: Markus Stockhausen=0A=
Cc: ovirt-users=0A=
Betreff: Re: [Users] noVNC with intermediate certificates=0A=
=0A=
Hi,=0A=
=0A=
Can you please try to specify=0A=
=0A=
SSL_CERTIFICATE=3Dxxx=0A=
=0A=
where xx contains the complete certificate chain in reverse?=0A=
=0A=
-----BEGIN CERTIFICATE-----=0A=
... (certificate for your server)...=0A=
-----END CERTIFICATE-----=0A=
-----BEGIN CERTIFICATE-----=0A=
... (the certificate for the CA)...=0A=
-----END CERTIFICATE-----=0A=
-----BEGIN CERTIFICATE-----=0A=
... (the root certificate for the CA's issuer)...=0A=
-----END CERTIFICATE-----=0A=
=0A=
Of course you need matching SSL_KEY.=0A=
=0A=
Regards,=0A=
Alon=0A=
=0A=
The tests say:=0A=
=0A=
The intermediate certificate is not really needed. The explanation=0A=
is quite simple. If you navigate to the admin page over https=0A=
the apache webserver presents the intermediate certificate. =0A=
This is temporarily stored in the (Firefox) browser. When you =0A=
open the noVNC console it is automatically trusted. =0A=
=0A=
BUT! You will still get a certificate warning if you navigate directly=0A=
to https://<server>:6100 after opening the browser.=0A=
=0A=
Nevertheless your hint seems to help. I just added the=0A=
intermediate certificate to the standard file =0A=
/etc/pki/ovirt-engine/certs/websocket-proxy.cer=0A=
and a direct connect to https://<server>:6100 gives=0A=
no warnings.=0A=
=0A=
Thanks.=0A=
=0A=
Markus=0A=
------=_NextPartTM-000-c9fbc65d-1b8a-45b7-96bc-aa2de25be96e
Content-Type: text/plain;
name="InterScan_Disclaimer.txt"
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
filename="InterScan_Disclaimer.txt"
****************************************************************************
Diese E-Mail enthält vertrauliche und/oder rechtlich geschützte
Informationen. Wenn Sie nicht der richtige Adressat sind oder diese E-Mail
irrtümlich erhalten haben, informieren Sie bitte sofort den Absender und
vernichten Sie diese Mail. Das unerlaubte Kopieren sowie die unbefugte
Weitergabe dieser Mail ist nicht gestattet.
Über das Internet versandte E-Mails können unter fremden Namen erstellt oder
manipuliert werden. Deshalb ist diese als E-Mail verschickte Nachricht keine
rechtsverbindliche Willenserklärung.
Collogia
Unternehmensberatung AG
Ubierring 11
D-50678 Köln
Vorstand:
Kadir Akin
Dr. Michael Höhnerbach
Vorsitzender des Aufsichtsrates:
Hans Kristian Langva
Registergericht: Amtsgericht Köln
Registernummer: HRB 52 497
This e-mail may contain confidential and/or privileged information. If you
are not the intended recipient (or have received this e-mail in error)
please notify the sender immediately and destroy this e-mail. Any
unauthorized copying, disclosure or distribution of the material in this
e-mail is strictly forbidden.
e-mails sent over the internet may have been written under a wrong name or
been manipulated. That is why this message sent as an e-mail is not a
legally binding declaration of intention.
Collogia
Unternehmensberatung AG
Ubierring 11
D-50678 Köln
executive board:
Kadir Akin
Dr. Michael Höhnerbach
President of the supervisory board:
Hans Kristian Langva
Registry office: district court Cologne
Register number: HRB 52 497
****************************************************************************
------=_NextPartTM-000-c9fbc65d-1b8a-45b7-96bc-aa2de25be96e--