On Wed, Jan 6, 2021 at 1:17 PM Gary Lloyd <g.lloyd@keele.ac.uk> wrote:

Hi please could someone point me in the right direction to renew ssl certificates for vdsm to communicate with ovirt 3.6 ?

I’m aware that this version hasn’t been supported for some time, this is a legacy environment which we are working towards decommissioning.

 

There seems to be a fix article for RHEV but we don’t have a subscription to view this information:

How to update expired RHEV certificates when all RHEV hosts got 'Non-responsive' - Red Hat Customer Portal

 

These are what the vdsm hosts are showing:

Reactor thread::ERROR::2021-01-06 11:04:59,505::m2cutils::337::ProtocolDetector.SSLHandshakeDispatcher::(handle_read) Error during handshake: sslv3 alert certificate expired

 

I have rerun engine-setup but this only seems to have fixed one of the vdsm hosts and the others are non responsive.

The others are in different clusters and we have some important services still running on these.


The "canonical" way is to "Reinstall" or "Enroll Certificates".

I think this will require stopping all VMs on them.

Good luck and best regards,
--
Didi