Bug 1374585 - [Docs] Missing steps to replace SSL Certificate
Summary: [Docs] Missing steps to replace SSL Certificate
Keywords:
Status: CLOSED DUPLICATE of bug 1336845
Alias: None
Product: Red Hat Enterprise Virtualization Manager
Classification: Red Hat
Component: Documentation
Version: 4.0.2
Hardware: x86_64
OS: Linux
unspecified
medium
Target Milestone: ovirt-4.0.5
: ---
Assignee: rhev-docs@redhat.com
QA Contact: rhev-docs@redhat.com
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-09-09 07:16 UTC by Germano Veit Michel
Modified: 2019-12-16 06:44 UTC (History)
8 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-10-05 05:21:35 UTC
oVirt Team: Docs
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Knowledge Base (Solution) 2610251 0 None None None 2016-09-09 07:30:43 UTC

Description Germano Veit Michel 2016-09-09 07:16:00 UTC
Description of problem:

This Guide:
https://access.redhat.com/documentation/en/red-hat-virtualization/4.0/single/administration-guide/#Replacing_the_SSL_certificate_used_by_Red_Hat_Enterprise_Virtualization_Manager_to_identify_itself_to_users_connecting_over_https

Is missing the steps from the "Doc Text" of this BZ: 
https://bugzilla.redhat.com/show_bug.cgi?id=1336838

Because a fresh install of 4.0 hit the same issue when following the Documentation.

The upgrade guide already contains a note regarding it - look at the BZ. But wouldn't it be preferable if the steps were properly outlined in the Documentation?

https://access.redhat.com/documentation/en/red-hat-virtualization/4.0/single/upgrade-guide/#Upgrading_to_Red_Hat_Virtualization_Manager_4.0

Actual results following the Documentation: 
admin@internal cannot login
ERROR [org.ovirt.engine.core.aaa.servlet.SsoPostLoginServlet] (default task-2) [] server_error: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

Expected results:
admin@internal logs in fine

Additional info:

I believe correct steps would be like this:
1. trust anchor /<path>/ca.crt && update-ca-trust
2. Follow the current docs
3. create /etc/ovirt-engine/engine.conf.d/99-custom-truststore.conf
   ENGINE_HTTPS_PKI_TRUST_STORE="/etc/pki/java/cacerts"
   ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD=""
4. service ovirt-engine restart

Comment 1 Tahlia Richardson 2016-10-05 05:21:35 UTC
Closing this bug as a duplicate of BZ#1336845. This bug helped clarify the other one for me, though, so thanks for raising it, Germano.

*** This bug has been marked as a duplicate of bug 1336845 ***


Note You need to log in before you can comment on or make changes to this bug.