Created attachment 1165567 [details]
curl error 22
Description of problem:
[RFE]Should give a better description about 'curl error 22' when failed using ssh identity http url at p2v client
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1.Check ssh identity info at virt-p2v manual page
SSH identity downloaded from a website. In the GUI, use:
│ Password: [ <leave this field blank> ] │
│ SSH Identity URL: [https://internal.example.com/id_rsa] │
or on the kernel command line:
Anyone could still download the private key and use it to log in to the virt-v2v conversion server, but you could provide some extra security by configuring the web server to only allow connections from P2V machines.
2.Create a key pair which must have an empty passphrase and let public key append to the authorized_keys file at conversion server
2.1#ssh-keygen -t rsa -N '' -f id_rsa
2.2#scp id_rsa.pub /root/.ssh/authorized_keys
3.Put the id_rsa at available website, such as http://pan.baidu.com/s/1qXFPzZm,
4.Boot the machine into p2v client via iso
5.At inputting conversion server info interface, input conversion ip and username and then input id_rsa http url at ssh identity url, then the connection failed with error: curl error 22, pls refer to screenshot 'curl error 22', but the failed reason is not very clear
As above description
Should give a better description about 'curl error 22' when failed to use ssh identity http url to connect conversion server at p2v client
I pushed this change which displays the full error message from
curl on failed downloads of the SSH identify URL.
Created attachment 1165659 [details]
This shows what the error looks like in the case of a 403 Forbidden
error of the type seen in bug 1343414.
That's basically all the information that curl gives us.
I can reproduce the bug on build:
Try to verify the bug with build:
1.Create a key pair which must have an empty passphrase and let public key append to the authorized_keys file at conversion server
1.1#ssh-keygen -t rsa -N '' -f id_rsa
1.2#scp id_rsa.pub /root/.ssh/authorized_keys
2.Mount the website to local
mount 10.73.194.27:/vol/S3/libvirtmanual/mxie /mnt
3.Copy the key to website
#cp id_rsa /mnt
4.Don't Change mode of the key, id_rsa has default mode: 0600
-rw-------. 1 root root 1675 Jun 24 2016 id_rsa
5.Boot the machine into p2v client via iso
6.At inputting conversion server info interface, input conversion ip and username and then input id_rsa http url at ssh identity url as http://fileshare.englab.nay.redhat.com/pub/section3/libvirtmanual/mxie/id_rsa
The error shows:http://fileshare.englab.nay.redhat.com/pub/section3/libvirtmanual/mxie/id_rsa:curl:(22)the requested URL returned error:403 Forbidden after step6.so the error reason is easy to understand now
So move the bug from ON_QA to VERIFIED
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.