<div dir="ltr"><div><div>Good morning ,<br><br>&quot;You
 need to have correctly set up engine FQDN and it has to be resolvable. 
If you don&#39;t have correctly set engine FQDN, you can fix that ​​using ovirt​-engine-rename tool, more info can be found at:<br><br><a href="https://www.ovirt.org/documentation/how-to/networking/changing-engine-hostname/" target="_blank">https://www.ovirt.org/<wbr>documentation/how-to/<wbr>networking/<span class="">changing</span>-engine-<wbr><span class="">hostname</span>/</a> &quot;<br><br></div>can I make the procedure with host and vms in production?<br><br></div>Thanks.<br></div><div class="gmail_extra"><br><div class="gmail_quote">2016-08-03 14:34 GMT-03:00 Martin Perina <span dir="ltr">&lt;<a href="mailto:mperina@redhat.com" target="_blank">mperina@redhat.com</a>&gt;</span>:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div class="gmail_default" style="font-family:arial,helvetica,sans-serif"><br></div><div class="gmail_extra"><br><div class="gmail_quote"><span class="">On Wed, Aug 3, 2016 at 5:25 PM, Fabrice Bacchella <span dir="ltr">&lt;<a href="mailto:fabrice.bacchella@icloud.com" target="_blank">fabrice.bacchella@icloud.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Next step :<br>
<br>
The UI says, even with a restarted navigator:<br>
<br>
org.codehaus.jackson.<wbr>JsonParseException: Unexpected character (&#39;&lt;&#39; (code 60)): expected a valid value (number, String, array, object, &#39;true&#39;, &#39;false&#39; or &#39;null&#39;) at [Source: java.io.StringReader@74749f78; line: 3, column: 2]<br></blockquote></span><div><br><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;display:inline">​I haven&#39;t seen this error before, could you please share server.log and engine.log?<br>​</div> </div><span class=""><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br>
<br>
I shift-reload, got a welcome screen, click on &quot;Administration portal&quot;. I then got a warning. The vhost for ovirt is &quot;ovirt.mydomain&quot;, but I got a redirect to:<br>
<a href="https://ovirt.mydomain/ovirt-engine/webadmin/sso/login?&amp;app_url=https%3A%2F%2Fovirt.mydomain%2Fovirt-engine%2Fwebadmin%2F%3Flocale%3Den_US&amp;locale=en_US" rel="noreferrer" target="_blank">https://ovirt.mydomain/ovirt-<wbr>engine/webadmin/sso/login?&amp;<wbr>app_url=https%3A%2F%2Fovirt.<wbr>mydomain%2Fovirt-engine%<wbr>2Fwebadmin%2F%3Flocale%3Den_<wbr>US&amp;locale=en_US</a><br>
that then redirect to:<br>
<a href="https://realhost.mydomain:443/ovirt-engine/sso/oauth/authorize?client_id=ovirt-engine-core&amp;response_type=code&amp;redirect_uri=https%3A%2F%2Fovirt.mydomain%3A443%2Fovirt-engine%2Fwebadmin%2Fsso%2Foauth2-callback&amp;scope=ovirt-app-admin+ovirt-app-portal+ovirt-ext%3Dauth%3Asequence-priority%3D%7E&amp;state=5ku3vXkfb10" rel="noreferrer" target="_blank">https://realhost.mydomain:443/<wbr>ovirt-engine/sso/oauth/<wbr>authorize?client_id=ovirt-<wbr>engine-core&amp;response_type=<wbr>code&amp;redirect_uri=https%3A%2F%<wbr>2Fovirt.mydomain%3A443%<wbr>2Fovirt-engine%2Fwebadmin%<wbr>2Fsso%2Foauth2-callback&amp;scope=<wbr>ovirt-app-admin+ovirt-app-<wbr>portal+ovirt-ext%3Dauth%<wbr>3Asequence-priority%3D%7E&amp;<wbr>state=5ku3vXkfb10</a><br>
<br>
And it fail with again with still:<br>
org.codehaus.jackson.<wbr>JsonParseException: Unexpected character (&#39;&lt;&#39; (code 60)): expected a valid value (number, String, array, object, &#39;true&#39;, &#39;false&#39; or &#39;null&#39;) at [Source: java.io.StringReader@328a4512; line: 3, column: 2]​ </blockquote><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br>
Many requests were send to ovirt.mydomain, but just one to realhost.mydomain:443, I don&#39;t know why.<br></blockquote></span><div><br><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;display:inline">​You need to have correctly set up engine FQDN and it has to be resolvable. If you don&#39;t have correctly set engine FQDN, you can fix that ​</div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;display:inline">​using ovirt​-engine-rename tool, more info can be found at:<br><br><a href="https://www.ovirt.org/documentation/how-to/networking/changing-engine-hostname/" target="_blank">https://www.ovirt.org/<wbr>documentation/how-to/<wbr>networking/changing-engine-<wbr>hostname/</a><br><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;display:inline">Also be aware that you need to use that engine FQDN to access oVirt 4.0<br><br></div></div><span class=""><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br>
I didn&#39;t ask for any SSO, I already use my own (CAS), it was working well and the update never ask for activating something new.<br></blockquote></span><div><br><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;display:inline">​This is one of the oVirt 4.0 features​, we have implemented OAUTH SSO for all engine parts: webadmin, userportal and restapi. If you are using CAS (althought it&#39;s officially supported by oVirt), that probably means you have configured cas authentication on Apache, passing authenticated username using aaa-misc as authn extension and aaa-ldap as authz extension (to get group memberships for authenticated user). If that&#39;s true then please take a look at <br><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=1342192" target="_blank">https://bugzilla.redhat.com/<wbr>show_bug.cgi?id=1342192</a><br><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;display:inline">there are some changes on Apache configuration (the bug is for kerberos, but I suspect similar config is needed also for cas module in apache).<br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;display:inline"><br></div></div><span class=""><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br>
<br>
&gt; Le 3 août 2016 à 15:09, Martin Perina &lt;<a href="mailto:mperina@redhat.com" target="_blank">mperina@redhat.com</a>&gt; a écrit :<br>
&gt;<br>
&gt; Hi,<br>
&gt; please follow steps as described in BZ:<br>
&gt;<br>
&gt; 1. Create /etc/ovirt-engine/engine.conf.<wbr>d/99-custom-truststore.conf (you may choose different filename but it has to end with &#39;.conf&#39; suffix) with following content:<br>
&gt;<br>
&gt;   ENGINE_HTTPS_PKI_TRUST_STORE=<wbr>&quot;&lt;full path to your java keystore&gt;&quot;<br>
&gt;   ENGINE_HTTPS_PKI_TRUST_STORE_<wbr>PASSWORD=&quot;&lt;password to your java keystore&gt;&quot;<br>
&gt;<br>
&gt; 2. Restart the engine<br>
&gt;<br>
&gt; If the above doesn&#39;t work please attach server.log/engine.log<br>
&gt;<br>
&gt; Thanks<br>
&gt;<br>
&gt; Martin Perina<br>
<br>
</blockquote></span></div><br></div></div>
<br>______________________________<wbr>_________________<br>
Users mailing list<br>
<a href="mailto:Users@ovirt.org">Users@ovirt.org</a><br>
<a href="http://lists.ovirt.org/mailman/listinfo/users" rel="noreferrer" target="_blank">http://lists.ovirt.org/<wbr>mailman/listinfo/users</a><br>
<br></blockquote></div><br></div>