When starting the libvirtd
service, I encountered the error: "The server certificate /etc/pki/libvirt/servercert.pem has expired."
#9565
-
ISSUE TYPE
COMPONENT NAME
CLOUDSTACK VERSION
CONFIGURATIONOS / ENVIRONMENTCentos 7.9 SUMMARYWhen starting the STEPS TO REPRODUCE
I can see that it's a symbolic link, with the source path being /etc/cloudstack/agent/cloud.crt. I checked the certificate's validity period using the command:
EXPECTED RESULTSI can see that it's a symbolic link, with the source path being /etc/cloudstack/agent/cloud.crt. I checked the certificate's validity period using the command:
It turns out the certificate has expired, which caused the error when I tried to restart the libvirtd service today. Should I create a self-signed certificate to replace it? If I do, will there be any impact due to context or dependencies? Or is there another solution? ACTUAL RESULTS
|
Beta Was this translation helpful? Give feedback.
Replies: 4 comments 2 replies
-
Thanks for opening your first issue here! Be sure to follow the issue template! |
Beta Was this translation helpful? Give feedback.
-
You can try the following steps
|
Beta Was this translation helpful? Give feedback.
-
感谢大佬!!!国人牛逼,但是我的这个ca.plugin.root.auth.strictness,我发现默认就是false关闭的,没有打开。这个东西在生产环境会有啥影响吗? |
Beta Was this translation helpful? Give feedback.
-
@LiuYanHao789 I don't understand your last comment. By re-provisioning certificate on all hosts and turning auth strictness to true is enough to secure your production env. See if you can upgrade to the most recent 4.18 release and have |
Beta Was this translation helpful? Give feedback.
You can try the following steps