Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1112863

Summary: [Docs] [CLI] http://[rhevm-server]/ca.crt is not always the correct CA certificate for rhevm-shell
Product: Red Hat Enterprise Virtualization Manager Reporter: Aram Agajanian <agajania>
Component: DocumentationAssignee: rhev-docs <rhev-docs>
Status: CLOSED WONTFIX QA Contact: Andrew Burden <aburden>
Severity: unspecified Docs Contact:
Priority: low    
Version: 3.3.0CC: adahms, cfergeau, gklein, juwu, rbalakri, srevivo, ylavi
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Build Name: 22457, Command Line Shell Guide-3.3-1 Build Date: 29-04-2014 13:25:07 Topic ID: 7555-591791 [Specified]
Last Closed: 2016-05-31 11:38:01 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: Docs RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1156381    

Description Aram Agajanian 2014-06-24 20:30:58 UTC
Title: TLS/SSL Certification

Describe the issue:
Your instructions say to use http://[rhevm-server]/ca.crt as the CA certificate for rhevm-shell.  However, that is the CA certificate for communication with the hosts.  It is not necessarily the CA certificate for the Apache web server, which is /etc/pki/ovirt-engine/apache-ca.pem.

The instructions for replacing the CA certificate for the Apache web server are at the following URL:

https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Virtualization/3.3/html/Administration_Guide/appe-Red_Hat_Enterprise_Virtualization_and_SSL.html

Suggestions for improvement:
If the Apache web server certificate has been replaced with a commercial certificate, then using /etc/pki/tls/certs/ca-bundle.crt as the CA certificate will work for rhevm-shell.

Comment 2 Andrew Dahms 2015-09-03 00:37:49 UTC
Changing status back to 'New' until re-assignment.

Comment 3 Yaniv Lavi 2016-05-09 11:07:08 UTC
oVirt 4.0 Alpha has been released, moving to oVirt 4.0 Beta target.

Comment 7 Yaniv Lavi 2016-05-31 11:38:01 UTC
The CLI is going to be deprecated in RHEV 4.0, so closing this item.