Bug 2078025 - [Docs] Now that certificates only last 13 months, RHV needs to document how to renew them
Summary: [Docs] Now that certificates only last 13 months, RHV needs to document how t...
Keywords:
Status: CLOSED NEXTRELEASE
Alias: None
Product: Red Hat Enterprise Virtualization Manager
Classification: Red Hat
Component: Documentation
Version: 4.4.10
Hardware: All
OS: All
urgent
urgent
Target Milestone: ovirt-4.5.0
: 4.5.0
Assignee: Eli Marcus
QA Contact: Guilherme Santos
ctomasko
URL:
Whiteboard: added docscope 4.5
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-04-22 21:41 UTC by Greg Scott
Modified: 2023-09-15 01:54 UTC (History)
15 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-05-18 12:52:14 UTC
oVirt Team: Infra
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Bugzilla 2079890 1 unspecified CLOSED renew certificates sooner before they expire 2022-05-30 06:48:15 UTC
Red Hat Issue Tracker RHV-45853 0 None None None 2022-04-22 21:50:32 UTC
Red Hat Knowledge Base (Solution) 3532921 0 None None None 2022-04-22 21:43:07 UTC
Red Hat Knowledge Base (Solution) 6865861 0 None None None 2022-04-22 21:41:17 UTC

Description Greg Scott 2022-04-22 21:41:18 UTC
Description of problem:
When a host certificate expires, that host goes non-responsive and becomes unmanageable. When Engine certificates expire, the admin and other web portals stop responding. All from the simple passage of time.

When this happens, the consequences range from unpleasant to catastrophic, especially for organizations that run critical VMs. Now that certificates only last 13 months, RHV needs to prominently document the consequences when they expire and how to renew them and avoid those unpleasant consequences. 

Version-Release number of selected component (if applicable):
4.4

How reproducible:
At will

Steps to Reproduce:
1. Build a RHV environment.
2. Operate it for 398 days without renewing host and Engine certificates.
3. 

Actual results:
Everything dies when the certificates expire.

Expected results:
The official documentation should warn customers about what will happen when the certificates expire and how to avoid it.

Additional info:
See https://access.redhat.com/solutions/6865861 for how to renew host and Engine certificates.

Certificate renewal should be a periodic administrative task, and so the logical place to document this is a new section 3.4 in the RHV 4.4 Administrator's Guide. Section 3.3 is Setting up errata viewing with Red Hat Satellite. The existing section 3.4 is Automating tasks using Ansible. Move the old section 3.4 to 3.5, 3.5 to 3.6, 3.6 to 3.7, and so forth, and insert a new section 3.4 titled, "You Must Renew Host and Engine Certificates Annually." Bold and italics on "Must." Use text from the above KCS solution to document how to renew the certificates and what will happen if not renewed.

Update the Release Notes to reference this new Admin Guide section. It might also make sense to reference it from the Upgrade Guide, since RHV certificate renewals were part of upgrades in older versions when certificates lasted five years.

Comment 5 Marina Kalinin 2022-04-27 02:25:53 UTC
Thank you, Donna!
Looks good to me.

Comment 8 Marina Kalinin 2022-04-28 17:34:26 UTC
BZ#2079890 will take care of early renewal of certificates during upgrades.

Comment 12 ctomasko 2022-05-05 13:23:36 UTC
https://github.com/oVirt/ovirt-site/pull/2866 link to doc PR

Comment 20 Red Hat Bugzilla 2023-09-15 01:54:06 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 365 days


Note You need to log in before you can comment on or make changes to this bug.