Description of problem: ovirt-provider-ovn.cer certificates don't get renewed during engine-setup Version-Release number of selected component (if applicable): ovirt-engine-4.5.0.7-0.9.el8ev.noarch How reproducible: Always Steps to Reproduce: 1. Run `engine-setup` when certificates are close to expiring Actual results: All certs get renewed, except for ovirt-provider-ovn.cer, ovn-ndb.cer, and ovn-sdb.cer This prevents ovsdb-server from functioning properly, and spams the logs with failed connection / ssl errors. Expected results: Certificates to get renewed when `engine-setup` is run Additional info: Warning when certificates are approaching (or reached) expiry date - i'll raise a separate BZ for that.
Verified on =========== ovirt-engine-4.5.2.3-0.1.el8ev.noarch ovirt-engine-setup-4.5.2.3-0.1.el8ev.noarch
I think "always" is too-strong here. They are always _handled_, in that we prompt the user asking what to do, like with other certs. Users that reply 'No', would be asked again on the next run of engine-setup. Current doc text sounds as we do not prompt and always renew.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Important: RHV Manager (ovirt-engine) [ovirt-4.5.2] bug fix and security update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2022:6393