[Users] unable to use spice-html5 in chrome due to certificate error

Frantisek Kobzik fkobzik at redhat.com
Mon Dec 9 05:05:58 EST 2013


Hello,

please import certificate authority (not only the certificate) into your browser. You can find basic instructions here: http://www.ovirt.org/Console_Client_Resources under "spice-html5" bullet.
After you download the CA file (https://<your engine address>/ca.crt), you can import it to chrome via "Settings->Show advanced settings->Manage certificates->Certificate authority subtab" using import button.

Cheers!
Frank

----- Original Message -----
From: "Gianluca Cecchi" <gianluca.cecchi at gmail.com>
To: "users" <users at ovirt.org>
Sent: Saturday, December 7, 2013 6:57:56 PM
Subject: [Users] unable to use spice-html5 in chrome due to certificate error

Hello,
I think I have configured all ok.
Fedora 19 with stable oVirt 3.3.1
>From another fedora 19 system I'm trying to use chrome
Version 31.0.1650.63

I get a black window when using spice html5 in console options

in  /var/log/messages of engine I get

Dec  7 18:51:16 tekkaman ovirt-websocket-proxy.py[22356]: 5: handler
exception: [Errno 336265225] _ssl.c:351: error:140B0009:SSL
routines:SSL_CTX_use_PrivateKey_file:PEM lib

So I think the problem has to be the configuration part of
Import CA of the engine in your browser

can anyone gives instructions for dummies to do this, please?
Then I'll put into the wiki when I'm able to use it... ;-)

I see that in engine I have under /etc/pki/ovirt-engine

lrwxrwxrwx. 1 root  root     6 Feb 10  2013 apache-ca.pem -> ca.pem
-rw-r--r--. 1 root  root   563 Feb 10  2013 cacert.conf
-rw-r--r--. 1 root  root   505 Feb 10  2013 cacert.template
-rw-r--r--. 1 root  root   384 Nov 14 12:44 cacert.template.in
-rw-r-----. 1 ovirt ovirt 4810 Feb 10  2013 ca.pem
-rw-r--r--. 1 root  root   557 Feb 10  2013 cert.conf
drwxr-xr-x. 2 ovirt ovirt 4096 Nov 14 12:44 certs
-rw-r--r--. 1 root  root   557 Feb 10  2013 cert.template
-rw-r--r--. 1 root  root   483 Nov 14 12:44 cert.template.in
-rw-r--r--. 1 ovirt ovirt  292 Feb 10  2013 database.txt
-rw-r--r--. 1 ovirt ovirt   20 Feb 10  2013 database.txt.attr
-rw-r--r--. 1 root  root    20 Feb 10  2013 database.txt.attr.old
-rw-r--r--. 1 root  root   225 Feb 10  2013 database.txt.old
drwxr-xr-x. 2 root  root  4096 Nov 14 12:44 keys
-rw-r--r--. 1 root  root   548 Nov 14 12:44 openssl.conf
drwxr-x---. 2 ovirt ovirt 4096 Nov 14 12:44 private
drwxr-xr-x. 2 ovirt ovirt 4096 Nov 14 12:44 requests
-rw-r--r--. 1 ovirt ovirt    3 Feb 10  2013 serial.txt
-rw-r--r--. 1 root  root     3 Feb 10  2013 serial.txt.old

I've tried to import ca.pem and I'm requested a password if I try to
import under certificates tab, while it seems to import if under
certification authorities tab, but I continue to get that error....

Thanks in advance,
Gianluca
_______________________________________________
Users mailing list
Users at ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


More information about the Users mailing list