Bug 1450293
| Summary: | After upgrade still can't connect to engine web ui with chrome 58 (due to missing subjectAltName) | ||
|---|---|---|---|
| Product: | [oVirt] ovirt-engine | Reporter: | Dominik Holler <dholler> |
| Component: | Setup.Engine | Assignee: | Yedidyah Bar David <didi> |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | Jiri Belka <jbelka> |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | 4.1.1 | CC: | amureini, apinnick, bugs, danken, derez, dholler, didi, jbelka, lsvaty, mkalinin, nsoffer, pstehlik, rhodain, stirabos, ylavi |
| Target Milestone: | ovirt-4.1.4 | Flags: | rule-engine:
ovirt-4.1+
rule-engine: exception+ lsvaty: testing_ack+ |
| Target Release: | 4.1.4 | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Enhancement | |
| Doc Text: |
Newer browsers require the subjectAltName extension in certificates for HTTPS. Previously (version 4.1.2 and later), engine-setup created certificates with subjectAltName for new setups, but did not update existing certificates during upgrade.
Now engine-setup can add subjectAltName to existing internal certificates, so that newer browsers will accept them.
|
Story Points: | --- |
| Clone Of: | 1449084 | Environment: | |
| Last Closed: | 2017-07-28 14:18:24 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | Integration | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1449084 | ||
| Bug Blocks: | 1430598, 1449503, 1471461 | ||
|
Description
Dominik Holler
2017-05-12 07:53:53 UTC
Target release should be placed once a package build is known to fix a issue. Since this bug is not modified, the target version has been reset. Please use target milestone to plan a fix for a oVirt release. ok, rhevm-4.1.4.1-0.1.el7.noarch
~~~
# openssl x509 -in /etc/pki/ovirt-engine/certs/apache.cer -text -noout | grep -A 1 'Subject Alternative Name'
# engine-setup
--== PKI CONFIGURATION ==--
One or more of the certificates should be renewed, because they expire soon, or include an invalid expiry date, or do not include the subjectAltName extension, which can cause them to be rejected by recent browsers.
If you choose "No", you will be asked again the next time you run Setup.
See https://access.redhat.com/solutions/1572983 for more details.
Renew certificates? (Yes, No) [No]: Yes
...
[ INFO ] Upgrading CA
...
[ INFO ] Restarting httpd
Web access is enabled at:
...
Internal CA 8C:2E:3A:81:7B:FD:F1:A8:95:74:4F:E5:32:5E:8C:6D:EA:CB:CA:FD
...
[ INFO ] Execution of setup completed successfully
# openssl x509 -in /etc/pki/ovirt-engine/certs/apache.cer -text -noout | grep -A 1 'Subject Alternative Name'
X509v3 Subject Alternative Name:
DNS:jbelka-vm4.example.com
~~~
tested with gChrome 59.0.3071.115
|