| Summary: | Aviary doesn't run over SSL with only one server/cert | ||
|---|---|---|---|
| Product: | Red Hat Enterprise MRG | Reporter: | Stanislav Graf <sgraf> |
| Component: | condor-aviary | Assignee: | Pete MacKinnon <pmackinn> |
| Status: | CLOSED NOTABUG | QA Contact: | MRG Quality Engineering <mrgqe-bugs> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | high | ||
| Version: | Development | CC: | matt |
| Target Milestone: | 2.1 | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2011-11-09 16:53:13 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Stanislav Graf
2011-11-09 13:03:11 UTC
After examining the serv.pem file generated by the QE procedure and reviewing the OpenSSL docs I believe that the problem is that the server's certificate must be the FIRST cert listed after the private key. Thus, serv.pem should appear (be generated) as:
Bag Attributes
friendlyName: serv_grid1.lab.bos.redhat.com
localKeyID: 5B D1 2E 09 23 7F 73 03 A1 0B B0 57 43 8D A1 42 47 A4 9A B0
Key Attributes: <No Attributes>
-----BEGIN PRIVATE KEY-----
MIICdwIBADANBgkqhkiG9w0BAQEFAASCAmEwggJdAgEAAoGBALG25YqqmQI8Ztpr
1E9cAfJWU8p602Gf0v4ezpllbugssJETNsB44uhgKZbRu+kr1Lg9mE1bL3XNKrdm
ueXOcoXf+qZnfRZSCnxZGeHxZgr9sCNB6RMlDO/difPhMhGxQp9zoZ+MraABj+uk
JJDvW9tBlEEbgeP3ljnyf5h5Ji+rAgMBAAECgYB0JWS/y99UZsWR2wdXFnrvNxxs
KPodw6bSDrBX8MMbWpnLNxOBl4A0/yQvPcPiEJNmFluDsyTBiOVyF+FHIDYX0gyE
XGxhpCd3OppUoDhDBNj4kwCeTfZtHFgvIkq5xP1q6TxlIu/TExFFX8vlbSLgU5f/
Oxry1e6yO2t7jJVfgQJBANXSaxyPtC2QXEaxvheteXKEgE9i2AI1bL8Eg8qw2zUs
2mU3BIkwY0JJNwpG+m7J5OX2XT+G1jhMj6S0MlB77jUCQQDUxR8HUBWiv8VnIApB
HXAvrVNP5jwyTje/JaToiy6MlgJpIAY33U8XOrOK8JZByaJCzIpU5B1s2JUb/Dlb
JuJfAkAk0Y/aIjCfa+1HyxF1mEyCWKiTguy5LKPmHIvpGh0VAf01Uoz4Zpmg72SH
44L6Es/UfWC/MKOwnBZcAR9s1npFAkEAgShz8HV93MC67SH295YOLvLxOvRRIFx4
3LDWTU+H31GEfxowjCLsyvYYXUQ0ghULSa9uXZ/n+NX0lftjOeD90wJBAJ/MqeYg
cIDdhsnnz3HmJQLUZe6ejMNWzxZ4KMLQst/h1p0sLg6YGgPhR/r/ultxVwC/97AU
q55O9IbC037MoAg=
-----END PRIVATE KEY-----
Bag Attributes
friendlyName: serv_grid1.lab.bos.redhat.com
localKeyID: 5B D1 2E 09 23 7F 73 03 A1 0B B0 57 43 8D A1 42 47 A4 9A B0
subject=/CN=grid1.lab.bos.redhat.com
issuer=/CN=CAcert
-----BEGIN CERTIFICATE-----
MIIBqTCCARKgAwIBAgICA+kwDQYJKoZIhvcNAQEFBQAwETEPMA0GA1UEAxMGQ0Fj
ZXJ0MB4XDTExMTEwOTE0NDU1MVoXDTIxMTEwOTE0NDU1MVowIzEhMB8GA1UEAxMY
Z3JpZDEubGFiLmJvcy5yZWRoYXQuY29tMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCB
iQKBgQCxtuWKqpkCPGbaa9RPXAHyVlPKetNhn9L+Hs6ZZW7oLLCREzbAeOLoYCmW
0bvpK9S4PZhNWy91zSq3ZrnlznKF3/qmZ30WUgp8WRnh8WYK/bAjQekTJQzv3Ynz
4TIRsUKfc6GfjK2gAY/rpCSQ71vbQZRBG4Hj95Y58n+YeSYvqwIDAQABMA0GCSqG
SIb3DQEBBQUAA4GBAECIhCFns4USFLocZ1fgC/v2NXhgt8rTvJboV3uJNsSIFYH/
44vpIBiKEniqTVk/7/125NUPlls+IaDaFBV+5Z71CpfHsp87AdrfMAnre4b0IAvk
ItmuGLigIWbF8uBSoVdDhL4s44c5CblyS57c6/y9YJBNulFN2rSGsCw/BKOK
-----END CERTIFICATE-----
Bag Attributes
friendlyName: CAnick
subject=/CN=CAcert
issuer=/CN=CAcert
-----BEGIN CERTIFICATE-----
MIIBlzCCAQCgAwIBAgICA+gwDQYJKoZIhvcNAQEFBQAwETEPMA0GA1UEAxMGQ0Fj
ZXJ0MB4XDTExMTEwOTE0NDU1MFoXDTIxMTEwOTE0NDU1MFowETEPMA0GA1UEAxMG
Q0FjZXJ0MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDLjaTM7v+QNl9//p9u
GSKpcAgmktW/ywRONlYevUGC/gz+Vrj+tHxBZdVimFdczGQ7oHp75kTNWfyUHOD1
1fSgyLT5B3ZMhpo75049551wy8mtFi0oOmpcld1DEwasWVifAw6U2qfDHiQnh7Ow
UhZbhOYRbpsy2KA75Nv7KTs+6QIDAQABMA0GCSqGSIb3DQEBBQUAA4GBADFwDgnM
OB3XRMhxpFlWuYD/yXLPho7ds2FJF/etM6zBKJCTgTPBgLcmnagr4wbaDeSdsrjg
M1Uxaqqyhoy1CuVC2FSxxobUHx43+rBnTr1QhT6WIzr3tVfdhgibx0EyMgkCJaE6
wKxv+KrR0ty9JBwI/4VpBt+vaGuZ1Zo4gqDV
-----END CERTIFICATE-----
This rearranged PEM file works in my testing.
|