Bug 1353441 - Docs: replace /ca.crt with "/ovirt-engine/services/pki-resource?resource=ca-certificate&format=X509-PEM-CA"
Summary: Docs: replace /ca.crt with "/ovirt-engine/services/pki-resource?resource=ca-c...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Enterprise Virtualization Manager
Classification: Red Hat
Component: Documentation
Version: 4.0.0
Hardware: Unspecified
OS: Unspecified
medium
unspecified
Target Milestone: ovirt-4.0.3
: 4.0.1
Assignee: Julie
QA Contact: rhev-docs@redhat.com
URL:
Whiteboard:
: 1362617 (view as bug list)
Depends On:
Blocks: 1360991
TreeView+ depends on / blocked
 
Reported: 2016-07-07 05:53 UTC by Yedidyah Bar David
Modified: 2016-09-09 01:45 UTC (History)
9 users (show)

Fixed In Version:
Doc Type: Release Note
Doc Text:
Previously, the Manager's CA certificate could be downloaded from: http://[engine-fqdn]/ca.crt. With this update, the URL to download the CA certificate has changed to: http://[engine-fqdn]/ovirt-engine/services/pki-resource?resource=ca-certificate&format=X509-PEM-CA. Existing clients that use the old URL must be updated to use the new one.
Clone Of:
Environment:
Last Closed: 2016-09-09 01:45:03 UTC
oVirt Team: Docs
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Comment 1 Lucy Bopf 2016-08-04 02:37:41 UTC
*** Bug 1362617 has been marked as a duplicate of this bug. ***

Comment 4 Yaniv Kaul 2016-08-22 07:25:12 UTC
Don't we break backwards compatibility this way? Don't we expect older clients to continue try and successfully retrieve the certificate from the old location?

Comment 5 Yaniv Kaul 2016-08-22 07:35:08 UTC
(In reply to Yaniv Kaul from comment #4)
> Don't we break backwards compatibility this way? Don't we expect older
> clients to continue try and successfully retrieve the certificate from the
> old location?

Example - https://github.com/GNOME/libgovirt/blob/f70802a769baa8113f26ba9287e453b9209d56f5/govirt/ovirt-proxy.c#L55

Comment 6 Yedidyah Bar David 2016-08-22 09:03:05 UTC
(In reply to Yaniv Kaul from comment #5)
> (In reply to Yaniv Kaul from comment #4)
> > Don't we break backwards compatibility this way? Don't we expect older
> > clients to continue try and successfully retrieve the certificate from the
> > old location?

That's a good question, but too late...

> 
> Example -
> https://github.com/GNOME/libgovirt/blob/
> f70802a769baa8113f26ba9287e453b9209d56f5/govirt/ovirt-proxy.c#L55

It's already affected - 4.0 was released several months ago.

Another question to ask is if we tried hard enough to inform users/3rd-parties about this. No idea about this. The ones that already contacted us and fixed their clients did this, AFAIK, only when they saw they are broken, when trying 4.0 or a beta.


Note You need to log in before you can comment on or make changes to this bug.