Bug 1685929 - [RFE] Support VNC encryption
Summary: [RFE] Support VNC encryption
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Virtualization Tools
Classification: Community
Component: virt-viewer
Version: unspecified
Hardware: Unspecified
OS: Unspecified
unspecified
high
Target Milestone: ---
Assignee: Daniel Berrangé
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2019-03-06 10:23 UTC by Liran Rotenberg
Modified: 2020-09-11 11:38 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2020-09-11 11:38:56 UTC
Embargoed:


Attachments (Terms of Use)

Description Liran Rotenberg 2019-03-06 10:23:25 UTC
Description of problem:
Regarding https://bugzilla.redhat.com/show_bug.cgi?id=1597085
Ovirt now supports VNC encryption, a integration for support it needed.


Additional info:
I tried both VV file and manually connect to the console without success.

Comment 1 Daniel Berrangé 2019-03-06 10:44:07 UTC
gtk-vnc and thus virt-viewer already support the VeNCrypt authentication scheme mentioned in that oVirt bugzilla.

If it isn't working then we need debugging info - please run with --gtk-vnc-debug and also provide details about what versions of virt-viewer & gtk-vnc you are using.

Comment 2 Liran Rotenberg 2019-03-26 10:06:20 UTC
virt-viewer version 5.0-2.fc26
virt-viewer-5.0-2.fc26.x86_64
gtk-vnc2-0.7.1-1.fc26.x86_64
remote-viewer version 5.0-2.fc26

Running the command:
# scp root@<host>:/etc/pki/vdsm/libvirt-vnc/ca-cert.pem ~/.pki/CA/cacert.pem
Then:
# virt-viewer -v --debug --gtk-vnc-debug  -c qemu+tls://root@<host_fqdn>/system golden_env_mixed_virtio_0
(virt-viewer:14396): virt-viewer-DEBUG: connecting ...
(virt-viewer:14396): virt-viewer-DEBUG: Opening connection to libvirt with URI qemu+tls://root@<host_fqdn>/system
Opening connection to libvirt with URI qemu+tls://root@<host_fqdn>/system
2019-03-26 09:53:37.923+0000: 14396: info : libvirt version: 3.7.0, package: 2.fc26 (Unknown, 2017-09-16-03:02:54, b0912341ddc545b49f91514142322b35)
2019-03-26 09:53:37.923+0000: 14396: info : hostname: localhost.localdomain
2019-03-26 09:53:37.923+0000: 14396: warning : virNetTLSContextCheckCertificate:1125 : Certificate check failed Certificate failed validation: The certificate hasn't got a known issuer.

# virsh -r dumpxml 9
<domain type='kvm' id='9'>
  <name>golden_env_mixed_virtio_0</name>
  <uuid>d7977a55-5d94-4c7b-9fc8-509bf37ba62f</uuid>
...
<graphics type='vnc' port='5903' autoport='yes' listen='10.35.30.6' keymap='en-us' passwdValidTo='2019-03-26T09:29:29'>
      <listen type='network' address='10.35.30.6' network='vdsm-ovirtmgmt'/>
    </graphics>

Using remote-viewer with VV file, there is no support for cert(only for spice). Opening the VV file open a window and immediately close.

Running in CLI:
remote-viewer -v --debug ~/Downloads/console.vv 
(remote-viewer:14640): virt-viewer-DEBUG: Opening display to ~/Downloads/console.vv
(remote-viewer:14640): virt-viewer-DEBUG: Guest (null) has a vnc display
Guest (null) has a vnc display
(remote-viewer:14640): virt-viewer-DEBUG: Start fetching oVirt main entry point
(remote-viewer:14640): virt-viewer-DEBUG: After open connection callback fd=-1
(remote-viewer:14640): virt-viewer-DEBUG: Opening connection to display at ~/Downloads/console.vv
Opening connection to display at ~/Downloads/console.vv
(remote-viewer:14640): virt-viewer-DEBUG: fullscreen display 0: 0
(remote-viewer:14640): virt-viewer-DEBUG: notebook show status 0x556a3ade0320
(remote-viewer:14640): virt-viewer-DEBUG: notebook show status 0x556a3ade0320
(remote-viewer:14640): virt-viewer-DEBUG: Insert display 0 0x556a3abd1680
(remote-viewer:14640): virt-viewer-DEBUG: notebook show status 0x556a3ade0320
(remote-viewer:14640): virt-viewer-DEBUG: Allocated 1024x740
(remote-viewer:14640): virt-viewer-DEBUG: Child allocate 1024x640

(remote-viewer:14640): Gtk-WARNING **: Allocating size to VncDisplay 0x556a3ae98250 without calling gtk_widget_get_preferred_width/height(). How does the code know the size to allocate?
(remote-viewer:14640): virt-viewer-DEBUG: Not removing main window 0 0x556a3abbdb60
(remote-viewer:14640): virt-viewer-DEBUG: Disconnected
(remote-viewer:14640): virt-viewer-DEBUG: close vnc=0x556a3ae98250
(remote-viewer:14640): virt-viewer-DEBUG: notebook show status 0x556a3ade0320
(remote-viewer:14640): virt-viewer-DEBUG: Guest (null) display has disconnected, shutting down
Guest (null) display has disconnected, shutting down

The .VV file:
[virt-viewer]
type=vnc
host=10.35.30.6
port=5903
password=<pass>
# Password is valid for 120 seconds.
delete-this-file=1
fullscreen=0
title=golden_env_mixed_virtio_0:%d
toggle-fullscreen=shift+f11
release-cursor=shift+f12
secure-attention=ctrl+alt+end
versions=rhev-win64:2.0-160;rhev-win32:2.0-160;rhel7:2.0-6;rhel6:99.0-1
newer-version-url=https://<engine_fqdn>/ovirt-engine/rhv/client-resources

[ovirt]
host=<engine_fqdn>:443
vm-guid=d7977a55-5d94-4c7b-9fc8-509bf37ba62f
sso-token=<sso_token>
admin=1
ca=-----BEGIN CERTIFICATE-----\n
...
\n-----END CERTIFICATE-----\n

Comment 3 Daniel Berrangé 2019-03-26 10:13:03 UTC
(In reply to Liran Rotenberg from comment #2)
> virt-viewer version 5.0-2.fc26
> virt-viewer-5.0-2.fc26.x86_64
> gtk-vnc2-0.7.1-1.fc26.x86_64
> remote-viewer version 5.0-2.fc26
> 
> Running the command:
> # scp root@<host>:/etc/pki/vdsm/libvirt-vnc/ca-cert.pem ~/.pki/CA/cacert.pem

This needs to be $HOME/.pki/libvirt/cacert.pem

> Then:
> # virt-viewer -v --debug --gtk-vnc-debug  -c
> qemu+tls://root@<host_fqdn>/system golden_env_mixed_virtio_0
> (virt-viewer:14396): virt-viewer-DEBUG: connecting ...
> (virt-viewer:14396): virt-viewer-DEBUG: Opening connection to libvirt with
> URI qemu+tls://root@<host_fqdn>/system
> Opening connection to libvirt with URI qemu+tls://root@<host_fqdn>/system
> 2019-03-26 09:53:37.923+0000: 14396: info : libvirt version: 3.7.0, package:
> 2.fc26 (Unknown, 2017-09-16-03:02:54, b0912341ddc545b49f91514142322b35)
> 2019-03-26 09:53:37.923+0000: 14396: info : hostname: localhost.localdomain
> 2019-03-26 09:53:37.923+0000: 14396: warning :
> virNetTLSContextCheckCertificate:1125 : Certificate check failed Certificate
> failed validation: The certificate hasn't got a known issuer.

This is simply a config mistake due to bad CA path above.


> Running in CLI:
> remote-viewer -v --debug ~/Downloads/console.vv 

I need the --gtk-vnc-debug  arg to be set too, as requested in the previous comment

Comment 4 Liran Rotenberg 2019-03-26 11:15:07 UTC
(In reply to Daniel Berrange from comment #3)
> (In reply to Liran Rotenberg from comment #2)
> > virt-viewer version 5.0-2.fc26
> > virt-viewer-5.0-2.fc26.x86_64
> > gtk-vnc2-0.7.1-1.fc26.x86_64
> > remote-viewer version 5.0-2.fc26
> > 
> > Running the command:
> > # scp root@<host>:/etc/pki/vdsm/libvirt-vnc/ca-cert.pem ~/.pki/CA/cacert.pem
> 
> This needs to be $HOME/.pki/libvirt/cacert.pem
> 
> > Then:
> > # virt-viewer -v --debug --gtk-vnc-debug  -c
> > qemu+tls://root@<host_fqdn>/system golden_env_mixed_virtio_0
> > (virt-viewer:14396): virt-viewer-DEBUG: connecting ...
> > (virt-viewer:14396): virt-viewer-DEBUG: Opening connection to libvirt with
> > URI qemu+tls://root@<host_fqdn>/system
> > Opening connection to libvirt with URI qemu+tls://root@<host_fqdn>/system
> > 2019-03-26 09:53:37.923+0000: 14396: info : libvirt version: 3.7.0, package:
> > 2.fc26 (Unknown, 2017-09-16-03:02:54, b0912341ddc545b49f91514142322b35)
> > 2019-03-26 09:53:37.923+0000: 14396: info : hostname: localhost.localdomain
> > 2019-03-26 09:53:37.923+0000: 14396: warning :
> > virNetTLSContextCheckCertificate:1125 : Certificate check failed Certificate
> > failed validation: The certificate hasn't got a known issuer.
> 
> This is simply a config mistake due to bad CA path above.
> 
Copying as suggested above gives:
# virt-viewer -v --debug --gtk-vnc-debug  -c qemu+tls://root@<host_fqdn>/system golden_env_mixed_virtio_0
(virt-viewer:15548): virt-viewer-DEBUG: connecting ...
(virt-viewer:15548): virt-viewer-DEBUG: Opening connection to libvirt with URI qemu+tls://root@<host_fqdn>/system
Opening connection to libvirt with URI qemu+tls://root@<host_fqdn>/system
(virt-viewer:15548): virt-viewer-DEBUG: Error: Unable to read TLS confirmation: Input/output error

> 
> > Running in CLI:
> > remote-viewer -v --debug ~/Downloads/console.vv 
> 
> I need the --gtk-vnc-debug  arg to be set too, as requested in the previous
> comment

remote-viewer -v --gtk-vnc-debug --debug ~/Downloads/console.vv 
(remote-viewer:15750): virt-viewer-DEBUG: Opening display to ~/Downloads/console.vv
(remote-viewer:15750): virt-viewer-DEBUG: Guest (null) has a vnc display
Guest (null) has a vnc display
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Init VncConnection=0x559187a1b510
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Using X11 backend
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c XKB keyboard map name 'evdev+aliases(qwerty)'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Server vendor is 'Fedora Project'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'Generic Event Extension'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'SHAPE'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'MIT-SHM'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XInputExtension'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XTEST'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'BIG-REQUESTS'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'SYNC'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XKEYBOARD'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XC-MISC'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XFIXES'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'RENDER'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'RANDR'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XINERAMA'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'Composite'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'DAMAGE'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'MIT-SCREEN-SAVER'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'DOUBLE-BUFFER'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'RECORD'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'DPMS'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'Present'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'DRI3'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'X-Resource'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XVideo'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XFree86-VidModeExtension'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XFree86-DGA'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'DRI2'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'GLX'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'SGI-GLX'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Using evdev keycode mapping
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplay.c Grab sequence is now Control_L+Alt_L
(remote-viewer:15750): virt-viewer-DEBUG: Start fetching oVirt main entry point
(remote-viewer:15750): virt-viewer-DEBUG: After open connection callback fd=-1
(remote-viewer:15750): virt-viewer-DEBUG: Opening connection to display at ~/Downloads/console.vv
Opening connection to display at ~/Downloads/console.vv
(remote-viewer:15750): virt-viewer-DEBUG: fullscreen display 0: 0
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Open host=10.35.30.6 port=5903
(remote-viewer:15750): virt-viewer-DEBUG: notebook show status 0x559187950320
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Open coroutine starting
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Started background coroutine
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Resolving host 10.35.30.6 5903
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Trying one socket
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Socket pending
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Finally connected
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Emit main context 13
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplay.c Grab sequence is now 
(remote-viewer:15750): virt-viewer-DEBUG: notebook show status 0x559187950320
(remote-viewer:15750): virt-viewer-DEBUG: Insert display 0 0x559187740680
(remote-viewer:15750): virt-viewer-DEBUG: notebook show status 0x559187950320
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplay.c Connected to VNC server
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Protocol initialization
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Server version: 3.8
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Sending full greeting
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Using version: 3.8
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Read error Resource temporarily unavailable
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Possible auth 19
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Emit main context 11
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Thinking about auth type 19
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Decided on auth type 19
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Waiting for auth type
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Choose auth 19
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Read error Resource temporarily unavailable
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Read error Resource temporarily unavailable
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Possible VeNCrypt sub-auth 261
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Emit main context 12
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Requested auth subtype 261
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Waiting for VeNCrypt auth subtype
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Choose auth 261
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Read error Resource temporarily unavailable
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Do TLS handshake
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c No CA certificate provided; trying the system trust store instead
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Using the system trust store and CRL
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c No client cert or key provided
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c No CA revocation list provided
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Handshake was blocking
(remote-viewer:15750): virt-viewer-DEBUG: Allocated 1024x740
(remote-viewer:15750): virt-viewer-DEBUG: Child allocate 1024x640

(remote-viewer:15750): Gtk-WARNING **: Allocating size to VncDisplay 0x559187a0a250 without calling gtk_widget_get_preferred_width/height(). How does the code know the size to allocate?
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Handshake was blocking
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Handshake done
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Validating
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Error: The certificate is not trusted
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Emit main context 16
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplay.c VNC server error
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Auth failed
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Doing final VNC cleanup
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Close VncConnection=0x559187a1b510
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Emit main context 15
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplay.c Disconnected from VNC server
(remote-viewer:15750): virt-viewer-DEBUG: Not removing main window 0 0x55918772d360
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplay.c Grab sequence is now 
(remote-viewer:15750): virt-viewer-DEBUG: Disconnected
(remote-viewer:15750): virt-viewer-DEBUG: close vnc=0x559187a0a250
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Init VncConnection=0x559188460220
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Using X11 backend
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c XKB keyboard map name 'evdev+aliases(qwerty)'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Server vendor is 'Fedora Project'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'Generic Event Extension'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'SHAPE'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'MIT-SHM'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XInputExtension'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XTEST'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'BIG-REQUESTS'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'SYNC'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XKEYBOARD'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XC-MISC'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XFIXES'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'RENDER'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'RANDR'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XINERAMA'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'Composite'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'DAMAGE'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'MIT-SCREEN-SAVER'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'DOUBLE-BUFFER'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'RECORD'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'DPMS'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'Present'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'DRI3'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'X-Resource'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XVideo'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XFree86-VidModeExtension'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'XFree86-DGA'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'DRI2'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'GLX'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Found extension 'SGI-GLX'
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplaykeymap.c Using evdev keycode mapping
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplay.c Grab sequence is now Control_L+Alt_L
(remote-viewer:15750): virt-viewer-DEBUG: notebook show status 0x559187950320
(remote-viewer:15750): virt-viewer-DEBUG: Guest (null) display has disconnected, shutting down
Guest (null) display has disconnected, shutting down
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplay.c Display destroy, requesting that VNC connection close
(remote-viewer:15750): gtk-vnc-DEBUG: vncdisplay.c Releasing VNC widget
(remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Finalize VncConnection=0x559188460220

Comment 5 Daniel Berrangé 2019-03-26 11:26:08 UTC
(In reply to Liran Rotenberg from comment #4)
> (In reply to Daniel Berrange from comment #3)
> > (In reply to Liran Rotenberg from comment #2)
> > > virt-viewer version 5.0-2.fc26
> > > virt-viewer-5.0-2.fc26.x86_64
> > > gtk-vnc2-0.7.1-1.fc26.x86_64
> > > remote-viewer version 5.0-2.fc26
> > > 
> > > Running the command:
> > > # scp root@<host>:/etc/pki/vdsm/libvirt-vnc/ca-cert.pem ~/.pki/CA/cacert.pem
> > 
> > This needs to be $HOME/.pki/libvirt/cacert.pem
> > 
> > > Then:
> > > # virt-viewer -v --debug --gtk-vnc-debug  -c
> > > qemu+tls://root@<host_fqdn>/system golden_env_mixed_virtio_0
> > > (virt-viewer:14396): virt-viewer-DEBUG: connecting ...
> > > (virt-viewer:14396): virt-viewer-DEBUG: Opening connection to libvirt with
> > > URI qemu+tls://root@<host_fqdn>/system
> > > Opening connection to libvirt with URI qemu+tls://root@<host_fqdn>/system
> > > 2019-03-26 09:53:37.923+0000: 14396: info : libvirt version: 3.7.0, package:
> > > 2.fc26 (Unknown, 2017-09-16-03:02:54, b0912341ddc545b49f91514142322b35)
> > > 2019-03-26 09:53:37.923+0000: 14396: info : hostname: localhost.localdomain
> > > 2019-03-26 09:53:37.923+0000: 14396: warning :
> > > virNetTLSContextCheckCertificate:1125 : Certificate check failed Certificate
> > > failed validation: The certificate hasn't got a known issuer.
> > 
> > This is simply a config mistake due to bad CA path above.
> > 
> Copying as suggested above gives:
> # virt-viewer -v --debug --gtk-vnc-debug  -c
> qemu+tls://root@<host_fqdn>/system golden_env_mixed_virtio_0
> (virt-viewer:15548): virt-viewer-DEBUG: connecting ...
> (virt-viewer:15548): virt-viewer-DEBUG: Opening connection to libvirt with
> URI qemu+tls://root@<host_fqdn>/system
> Opening connection to libvirt with URI qemu+tls://root@<host_fqdn>/system
> (virt-viewer:15548): virt-viewer-DEBUG: Error: Unable to read TLS
> confirmation: Input/output error

The TLS connection handshake completed, but the server has dropped the connection. Possibly it is configured to require a client certificate 


> > > Running in CLI:
> > > remote-viewer -v --debug ~/Downloads/console.vv 
> > 
> > I need the --gtk-vnc-debug  arg to be set too, as requested in the previous
> > comment


> (remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Do TLS handshake
> (remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c No CA certificate
> provided; trying the system trust store instead

Ok, you've not provided a CA cert, so it is using the system trust. This is almost never what you want, as few people ever use public CAs to get certs for their QEMU servers.
So this is likely going to fail to validate certs later

> (remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Using the system trust
> store and CRL
> (remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c No client cert or key
> provided
> (remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c No CA revocation list
> provided
> (remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Handshake was blocking
> (remote-viewer:15750): virt-viewer-DEBUG: Allocated 1024x740
> (remote-viewer:15750): virt-viewer-DEBUG: Child allocate 1024x640
> 
> (remote-viewer:15750): Gtk-WARNING **: Allocating size to VncDisplay
> 0x559187a0a250 without calling gtk_widget_get_preferred_width/height(). How
> does the code know the size to allocate?
> (remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Handshake was blocking
> (remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Handshake done
> (remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Validating
> (remote-viewer:15750): gtk-vnc-DEBUG: vncconnection.c Error: The certificate
> is not trusted

Here it has failed to validate the server's cert, due to the missing CA cert above

gtk-vnc looks in /etc/pki/CA/cacert.pem and $HOME/.pki/CA/cacert.pem (yes different path from libvirt)

Comment 6 Liran Rotenberg 2019-04-10 12:15:00 UTC
Hi,
Copying the CA into $HOME/.pki/CA/cacert.pem works with a different version.
remote-viewer version 5.0-11.el7 (OS ID: rhel7)
virt-viewer-5.0-11.el7.x86_64
gtk-vnc2-0.7.0-3.el7.x86_64

I didn't manage to check a newer version in fedora. 
But, seems like this issue already fixed in newer versions.

You may consider closing this bug.


Note You need to log in before you can comment on or make changes to this bug.