Bug 2078025

Summary: [Docs] Now that certificates only last 13 months, RHV needs to document how to renew them
Product: Red Hat Enterprise Virtualization Manager Reporter: Greg Scott <gscott>
Component: DocumentationAssignee: Eli Marcus <emarcus>
Status: CLOSED NEXTRELEASE QA Contact: Guilherme Santos <gdeolive>
Severity: urgent Docs Contact: ctomasko <ctomasko>
Priority: urgent    
Version: 4.4.10CC: apinnick, ctomasko, ddacosta, didi, emarcus, lmurthy, lsurette, lsvaty, mavital, mhicks, mkalinin, mperina, mwest, srevivo, usurse
Target Milestone: ovirt-4.5.0Keywords: Documentation, Reopened
Target Release: 4.5.0   
Hardware: All   
OS: All   
Whiteboard: added docscope 4.5
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-05-18 12:52:14 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: Infra RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Greg Scott 2022-04-22 21:41:18 UTC
Description of problem:
When a host certificate expires, that host goes non-responsive and becomes unmanageable. When Engine certificates expire, the admin and other web portals stop responding. All from the simple passage of time.

When this happens, the consequences range from unpleasant to catastrophic, especially for organizations that run critical VMs. Now that certificates only last 13 months, RHV needs to prominently document the consequences when they expire and how to renew them and avoid those unpleasant consequences. 

Version-Release number of selected component (if applicable):
4.4

How reproducible:
At will

Steps to Reproduce:
1. Build a RHV environment.
2. Operate it for 398 days without renewing host and Engine certificates.
3. 

Actual results:
Everything dies when the certificates expire.

Expected results:
The official documentation should warn customers about what will happen when the certificates expire and how to avoid it.

Additional info:
See https://access.redhat.com/solutions/6865861 for how to renew host and Engine certificates.

Certificate renewal should be a periodic administrative task, and so the logical place to document this is a new section 3.4 in the RHV 4.4 Administrator's Guide. Section 3.3 is Setting up errata viewing with Red Hat Satellite. The existing section 3.4 is Automating tasks using Ansible. Move the old section 3.4 to 3.5, 3.5 to 3.6, 3.6 to 3.7, and so forth, and insert a new section 3.4 titled, "You Must Renew Host and Engine Certificates Annually." Bold and italics on "Must." Use text from the above KCS solution to document how to renew the certificates and what will happen if not renewed.

Update the Release Notes to reference this new Admin Guide section. It might also make sense to reference it from the Upgrade Guide, since RHV certificate renewals were part of upgrades in older versions when certificates lasted five years.

Comment 5 Marina Kalinin 2022-04-27 02:25:53 UTC
Thank you, Donna!
Looks good to me.

Comment 8 Marina Kalinin 2022-04-28 17:34:26 UTC
BZ#2079890 will take care of early renewal of certificates during upgrades.

Comment 12 ctomasko 2022-05-05 13:23:36 UTC
https://github.com/oVirt/ovirt-site/pull/2866 link to doc PR

Comment 20 Red Hat Bugzilla 2023-09-15 01:54:06 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 365 days