Self-Hosted Engine Deployment - Certificate Cannot be Found

This is a multipart message in MIME format. ------=_NextPart_000_014A_01D169F6.DF5165E0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Aloha, I am looking for assistance with an Ovirt Self-Hosted Engine Deployment on Centos 7.2. I have the host configured, and have accessed the VM (Engine). I run engine setup on the VM in accordance with the http://www.ovirt.org/Hosted_Engine_Howto page on the Wiki, with the exception of Automatically executing "Engine Setup" on the VM. Because of my configuration, I have to manually enter the network settings on the VM before it has network access, and then execute engine setup automatically. Particularly notable is that I enter the selection to automatically configure Apache to use a self-signed SSL during the Engine-Setup. The Engine-Setup completes successfully on the VM, I reboot, and verify that the web page is accessible and that I can log in to the engine. Then I return to the host to enter option 1 (Continue Setup - Ovirt Engine Installation is Ready and Engine service is up) and continue with the installation. The Engine Replies: DB Up! And acquires the internal CA cert from the engine. It lists the cert and then attempts to connect to the engine. The installation asks me to enter the name of the Cluster to which I want to add the host and I enter the automatic "Default" option. At this point the installation returns an error: Cannot automatically add the host to cluster Default: Cannot add Host. Connecting to host via SSH has failed, verify that the host is reachable (IP address, routable address, etc.) You may refer to the engine.log file for further details. Some notes: 1. The /etc/hosts/ file is configured on both host and engine, with ip and fqdn 2. Password-Less SSH is enable between both host and engine, bidirectionally. 3. Ping responds to both servers. DNS resolves on both servers. 4. SSH-Keygen was use to generate key, and key was stored in default Centos location /root/.ssh/id_rsa 5. Ssh-copy-id was used to copy the key to engine from host and vice versa. No password on key. I have managed to get this error to change by copying the contents of the /root/.ssh/id_rsa key to the /etc/pki/ovirt-engine/keys/engine.p12 location. When I attempt to "Continue setup - Engine VM configuration has been fixed" from this point, the error message changes slightly to: "Cannot automatically add the host to cluster Default: Cannot add new host using a secured connection, Certificate file could not be found. Some Notes: 1. I have ran the "Certificate and/or SSL problems?" procedures on www.ovirt.org/Node_Troubleshooting <http://www.ovirt.org/Node_Troubleshooting> " to verify the vdsm cert on the host. It returns a normal response. Can someone provide some assistance with this issue? I have attempted every work around that I know, and researched every source at my disposal to no avail. This issue has been plaguing me for the last three weeks. I have restarted the installation multiple times from fresh installs of the engine, the host, and both, and still no change up to this point. Thank you! Trenton D Warren President and CEO, Phoenix Holdings Corporation Main Office: 41-745 Mooiki ST. Waimanalo, HI 96795 Office: (808) 263-7448 Direct: (808) 263-7449 Cell: (478) 867-3107 Web: www.phoenixhawaii.net ------=_NextPart_000_014A_01D169F6.DF5165E0 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" = xmlns:o=3D"urn:schemas-microsoft-com:office:office" = xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" = xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta = http-equiv=3DContent-Type content=3D"text/html; = charset=3Dus-ascii"><meta name=3DGenerator content=3D"Microsoft Word 15 = (filtered medium)"><style><!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; margin-bottom:.0001pt; font-size:11.0pt; font-family:"Calibri",sans-serif;} a:link, span.MsoHyperlink {mso-style-priority:99; color:#0563C1; text-decoration:underline;} a:visited, span.MsoHyperlinkFollowed {mso-style-priority:99; color:#954F72; text-decoration:underline;} p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph {mso-style-priority:34; margin-top:0in; margin-right:0in; margin-bottom:0in; margin-left:.5in; margin-bottom:.0001pt; font-size:11.0pt; font-family:"Calibri",sans-serif;} span.EmailStyle17 {mso-style-type:personal-compose; font-family:"Calibri",sans-serif; color:windowtext;} .MsoChpDefault {mso-style-type:export-only; font-family:"Calibri",sans-serif;} @page WordSection1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in;} div.WordSection1 {page:WordSection1;} /* List Definitions */ @list l0 {mso-list-id:357246260; mso-list-type:hybrid; mso-list-template-ids:-1360869520 67698703 67698713 67698715 67698703 = 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 {mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in;} @list l0:level2 {mso-level-number-format:alpha-lower; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in;} @list l0:level3 {mso-level-number-format:roman-lower; mso-level-tab-stop:none; mso-level-number-position:right; text-indent:-9.0pt;} @list l0:level4 {mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in;} @list l0:level5 {mso-level-number-format:alpha-lower; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in;} @list l0:level6 {mso-level-number-format:roman-lower; mso-level-tab-stop:none; mso-level-number-position:right; text-indent:-9.0pt;} @list l0:level7 {mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in;} @list l0:level8 {mso-level-number-format:alpha-lower; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in;} @list l0:level9 {mso-level-number-format:roman-lower; mso-level-tab-stop:none; mso-level-number-position:right; text-indent:-9.0pt;} @list l1 {mso-list-id:1796868197; mso-list-type:hybrid; mso-list-template-ids:1349830608 67698703 67698713 67698715 67698703 = 67698713 67698715 67698703 67698713 67698715;} @list l1:level1 {mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in;} @list l1:level2 {mso-level-number-format:alpha-lower; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in;} @list l1:level3 {mso-level-number-format:roman-lower; mso-level-tab-stop:none; mso-level-number-position:right; text-indent:-9.0pt;} @list l1:level4 {mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in;} @list l1:level5 {mso-level-number-format:alpha-lower; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in;} @list l1:level6 {mso-level-number-format:roman-lower; mso-level-tab-stop:none; mso-level-number-position:right; text-indent:-9.0pt;} @list l1:level7 {mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in;} @list l1:level8 {mso-level-number-format:alpha-lower; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in;} @list l1:level9 {mso-level-number-format:roman-lower; mso-level-tab-stop:none; mso-level-number-position:right; text-indent:-9.0pt;} ol {margin-bottom:0in;} ul {margin-bottom:0in;} --></style><!--[if gte mso 9]><xml> <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext=3D"edit"> <o:idmap v:ext=3D"edit" data=3D"1" /> </o:shapelayout></xml><![endif]--></head><body lang=3DEN-US = link=3D"#0563C1" vlink=3D"#954F72"><div class=3DWordSection1><p = class=3DMsoNormal>Aloha,<o:p></o:p></p><p = class=3DMsoNormal><o:p> </o:p></p><p class=3DMsoNormal>I am looking = for assistance with an Ovirt Self-Hosted Engine Deployment on Centos = 7.2.<o:p></o:p></p><p class=3DMsoNormal><o:p> </o:p></p><p = class=3DMsoNormal>I have the host configured, and have accessed the VM = (Engine). I run engine setup on the VM in accordance with the = <i><a = href=3D"http://www.ovirt.org/Hosted_Engine_Howto">http://www.ovirt.org/Ho= sted_Engine_Howto</a> </i>page on the Wiki, with the exception of = Automatically executing “Engine Setup” on the VM. = Because of my configuration, I have to manually enter the network = settings on the VM before it has network access, and then execute engine = setup automatically. Particularly notable is that I enter the = selection to automatically configure Apache to use a self-signed SSL = during the Engine-Setup.<o:p></o:p></p><p = class=3DMsoNormal><o:p> </o:p></p><p class=3DMsoNormal>The = Engine-Setup completes successfully on the VM, I reboot, and verify that = the web page is accessible and that I can log in to the engine. = Then I return to the host to enter option 1 (Continue Setup – = Ovirt Engine Installation is Ready and Engine service is up) and = continue with the installation. <o:p></o:p></p><p = class=3DMsoNormal><o:p> </o:p></p><p class=3DMsoNormal>The Engine = Replies: DB Up! And acquires the internal CA cert from the engine. = It lists the cert and then attempts to connect to the engine. The = installation asks me to enter the name of the Cluster to which I want to = add the host and I enter the automatic “Default” = option. <o:p></o:p></p><p = class=3DMsoNormal><o:p> </o:p></p><p class=3DMsoNormal>At this = point the installation returns an error: Cannot automatically add the = host to cluster Default: Cannot add Host. Connecting to host via = SSH has failed, verify that the host is reachable (IP address, routable = address, etc.) You may refer to the engine.log file for further = details.<o:p></o:p></p><p class=3DMsoNormal><o:p> </o:p></p><p = class=3DMsoNormal>Some notes: <o:p></o:p></p><p class=3DMsoListParagraph = style=3D'text-indent:-.25in;mso-list:l0 level1 lfo1'><![if = !supportLists]><span style=3D'mso-list:Ignore'>1.<span = style=3D'font:7.0pt "Times New = Roman"'> = </span></span><![endif]> The /etc/hosts/ file is configured on both = host and engine, with ip and fqdn<o:p></o:p></p><p = class=3DMsoListParagraph style=3D'text-indent:-.25in;mso-list:l0 level1 = lfo1'><![if !supportLists]><span style=3D'mso-list:Ignore'>2.<span = style=3D'font:7.0pt "Times New = Roman"'> = </span></span><![endif]>Password-Less SSH is enable between both host = and engine, bidirectionally.<o:p></o:p></p><p class=3DMsoListParagraph = style=3D'text-indent:-.25in;mso-list:l0 level1 lfo1'><![if = !supportLists]><span style=3D'mso-list:Ignore'>3.<span = style=3D'font:7.0pt "Times New = Roman"'> = </span></span><![endif]>Ping responds to both servers. DNS = resolves on both servers.<o:p></o:p></p><p class=3DMsoListParagraph = style=3D'text-indent:-.25in;mso-list:l0 level1 lfo1'><![if = !supportLists]><span style=3D'mso-list:Ignore'>4.<span = style=3D'font:7.0pt "Times New = Roman"'> = </span></span><![endif]>SSH-Keygen was use to generate key, and key was = stored in default Centos location /root/.ssh/id_rsa<o:p></o:p></p><p = class=3DMsoListParagraph style=3D'text-indent:-.25in;mso-list:l0 level1 = lfo1'><![if !supportLists]><span style=3D'mso-list:Ignore'>5.<span = style=3D'font:7.0pt "Times New = Roman"'> = </span></span><![endif]>Ssh-copy-id was used to copy the key to engine = from host and vice versa. No password on key.<o:p></o:p></p><p = class=3DMsoNormal><o:p> </o:p></p><p class=3DMsoNormal>I have = managed to get this error to change by copying the contents of the = /root/.ssh/id_rsa key to the /etc/pki/ovirt-engine/keys/engine.p12 = location. <o:p></o:p></p><p = class=3DMsoNormal><o:p> </o:p></p><p class=3DMsoNormal>When I = attempt to “Continue setup – Engine VM configuration has = been fixed” from this point, the error message changes slightly = to: “Cannot automatically add the host to cluster Default: Cannot = add new host using a secured connection, Certificate file could not be = found.<o:p></o:p></p><p class=3DMsoNormal><o:p> </o:p></p><p = class=3DMsoNormal>Some Notes:<o:p></o:p></p><p class=3DMsoListParagraph = style=3D'text-indent:-.25in;mso-list:l1 level1 lfo2'><![if = !supportLists]><span style=3D'mso-list:Ignore'>1.<span = style=3D'font:7.0pt "Times New = Roman"'> </span></span><![endif]>I = have ran the “Certificate and/or SSL problems?” procedures = on <i><a = href=3D"http://www.ovirt.org/Node_Troubleshooting">www.ovirt.org/Node_Tro= ubleshooting</a>”</i> to verify the vdsm cert on the = host. It returns a normal response. <o:p></o:p></p><p = class=3DMsoNormal><o:p> </o:p></p><p class=3DMsoNormal>Can someone = provide some assistance with this issue? I have attempted every = work around that I know, and researched every source at my disposal to = no avail. This issue has been plaguing me for the last three = weeks. I have restarted the installation multiple times from fresh = installs of the engine, the host, and both, and still no change up to = this point.<o:p></o:p></p><p class=3DMsoNormal><o:p> </o:p></p><p = class=3DMsoNormal>Thank you!<o:p></o:p></p><p = class=3DMsoNormal><o:p> </o:p></p><p class=3DMsoNormal><b><span = style=3D'font-size:14.0pt'>Trenton D Warren<o:p></o:p></span></b></p><p = class=3DMsoNormal><i>President and CEO, Phoenix Holdings = Corporation<o:p></o:p></i></p><p class=3DMsoNormal><span = style=3D'font-size:9.0pt'>Main Office: 41-745 Mooiki ST. Waimanalo, HI = 96795<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:9.0pt'>Office: (808) = 263-7448<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:9.0pt'>Direct: (808) = 263-7449<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:9.0pt'>Cell: = (478) 867-3107<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:9.0pt'>Web: = www.phoenixhawaii.net<o:p></o:p></span></p><p = class=3DMsoNormal><o:p> </o:p></p></div></body></html> ------=_NextPart_000_014A_01D169F6.DF5165E0--

On Thu, Feb 18, 2016 at 1:48 PM, Trenton D Warren <twarren@phoenixhawaii.net
wrote:
Aloha,
I am looking for assistance with an Ovirt Self-Hosted Engine Deployment on Centos 7.2.
I have the host configured, and have accessed the VM (Engine). I run engine setup on the VM in accordance with the *http://www.ovirt.org/Hosted_Engine_Howto <http://www.ovirt.org/Hosted_Engine_Howto> *page on the Wiki, with the exception of Automatically executing “Engine Setup” on the VM. Because of my configuration, I have to manually enter the network settings on the VM before it has network access, and then execute engine setup automatically. Particularly notable is that I enter the selection to automatically configure Apache to use a self-signed SSL during the Engine-Setup.
The Engine-Setup completes successfully on the VM, I reboot, and verify that the web page is accessible and that I can log in to the engine. Then I return to the host to enter option 1 (Continue Setup – Ovirt Engine Installation is Ready and Engine service is up) and continue with the installation.
The Engine Replies: DB Up! And acquires the internal CA cert from the engine. It lists the cert and then attempts to connect to the engine. The installation asks me to enter the name of the Cluster to which I want to add the host and I enter the automatic “Default” option.
At this point the installation returns an error: Cannot automatically add the host to cluster Default: Cannot add Host. Connecting to host via SSH has failed, verify that the host is reachable (IP address, routable address, etc.) You may refer to the engine.log file for further details.
Some notes:
1. The /etc/hosts/ file is configured on both host and engine, with ip and fqdn
No one of the manual actions at points 2, 4, 5 is required: hosted-engine-setup will automatically download and deploy the engine SSH pub key from the engine before calling host.add on the REST API. I'm not sure about what will happen if you manually tweaked the sshd configuration on the host before that. Can you please attach hosted-engine-setup logs fro mthe host and engine.log fro the engine VM?
2. Password-Less SSH is enable between both host and engine, bidirectionally.
3. Ping responds to both servers. DNS resolves on both servers.
4. SSH-Keygen was use to generate key, and key was stored in default Centos location /root/.ssh/id_rsa
5. Ssh-copy-id was used to copy the key to engine from host and vice versa. No password on key.
I have managed to get this error to change by copying the contents of the /root/.ssh/id_rsa key to the /etc/pki/ovirt-engine/keys/engine.p12 location.
When I attempt to “Continue setup – Engine VM configuration has been fixed” from this point, the error message changes slightly to: “Cannot automatically add the host to cluster Default: Cannot add new host using a secured connection, Certificate file could not be found.
Some Notes:
1. I have ran the “Certificate and/or SSL problems?” procedures on *www.ovirt.org/Node_Troubleshooting <http://www.ovirt.org/Node_Troubleshooting>”* to verify the vdsm cert on the host. It returns a normal response.
Can someone provide some assistance with this issue? I have attempted every work around that I know, and researched every source at my disposal to no avail. This issue has been plaguing me for the last three weeks. I have restarted the installation multiple times from fresh installs of the engine, the host, and both, and still no change up to this point.
Thank you!
*Trenton D Warren*
*President and CEO, Phoenix Holdings Corporation*
Main Office: 41-745 Mooiki ST. Waimanalo, HI 96795
Office: (808) 263-7448
Direct: (808) 263-7449
Cell: (478) 867-3107
Web: www.phoenixhawaii.net
_______________________________________________ Users mailing list Users@ovirt.org http://lists.ovirt.org/mailman/listinfo/users
participants (2)
-
Simone Tiraboschi
-
Trenton D Warren