Bug 2088446 - pki enroll request failure
Summary: pki enroll request failure
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: ovirt-engine
Classification: oVirt
Component: ovirt-host-deploy-ansible
Version: 4.5.0.8
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ovirt-4.5.2
: 4.5.2
Assignee: Dana
QA Contact: Pavol Brilla
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-05-19 13:10 UTC by Dana
Modified: 2022-08-30 08:47 UTC (History)
5 users (show)

Fixed In Version: ovirt-engine-4.5.2
Clone Of:
Environment:
Last Closed: 2022-08-30 08:47:42 UTC
oVirt Team: Infra
Embargoed:
mperina: ovirt-4.5+
gdeolive: testing_ack+


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github oVirt ovirt-engine pull 558 0 None Merged pki: make openssl database non-writable for others 2022-08-02 07:30:22 UTC
Red Hat Issue Tracker RHV-46098 0 None None None 2022-05-19 13:17:04 UTC

Description Dana 2022-05-19 13:10:08 UTC
Description of problem:
OST failed on TASK [ovirt-host-deploy-vdsm-certificates : Run PKI enroll request for vdsm and QEMU] *** with the error: 'unable to rename serial.txt.new to serial.txt reason: No such file or directory Cannot sign certificate

concurrent deploy (https://bugzilla.redhat.com/show_bug.cgi?id=1990446) was fixed by using ${CA_FILE} as the lock file.

1. a different flock is needed (use /etc/pki/ovirt-engine/ca.pem)
2. fix umask in ansible call to pki-enroll


Version-Release number of selected component (if applicable):


How reproducible:


Steps to Reproduce:
1.
2.
3.

Actual results:


Expected results:


Additional info:

Comment 2 Sandro Bonazzola 2022-08-02 07:31:32 UTC
git tag --contains 3e0b763e86b66bd4cfaf4b2ebaf8f04a5e003d5a
ovirt-engine-4.5.2

Comment 3 Pavol Brilla 2022-08-08 07:41:19 UTC
2022-08-05 12:27:05 IDT - TASK [ovirt-host-deploy-vdsm-certificates : Run PKI enroll request for vdsm and QEMU] ***
message output doesnt contain any error messages

# yum list ovirt-engine
ovirt-engine.noarch                                                                     4.5.2-0.3.el8ev

Comment 4 Sandro Bonazzola 2022-08-30 08:47:42 UTC
This bugzilla is included in oVirt 4.5.2 release, published on August 10th 2022.
Since the problem described in this bug report should be resolved in oVirt 4.5.2 release, it has been closed with a resolution of CURRENT RELEASE.
If the solution does not work for you, please open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.