Re: [pve-devel] spice: problems when installing new certificate
On Mon, 12 Jan 2015 01:59:22 +0100 Michael Rasmussen m...@datanom.net wrote: I have an idea that the migration of the spiceproxy has something to do with it. What exactly does a migration of the spiceproxy which is not done by restarting the spiceproxy? Nobody observed this? -- Hilsen/Regards Michael Rasmussen Get my public GnuPG keys: michael at rasmussen dot cc http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0xD3C9A00E mir at datanom dot net http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0xE501F51C mir at miras dot org http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0xE3E80917 -- /usr/games/fortune -es says: It's not reality or how you perceive things that's important -- it's what you're taking for it... pgpuCS6J1dgt5.pgp Description: OpenPGP digital signature ___ pve-devel mailing list pve-devel@pve.proxmox.com http://pve.proxmox.com/cgi-bin/mailman/listinfo/pve-devel
Re: [pve-devel] spice: problems when installing new certificate
Nobody observed this? I never test upgrade of certificates and spice. certificates are used in spiceproxy, but maybe certifcates are also used by qemu process, so maybe we need to restart (or migrate) qemu guests to have new certificate working? - Mail original - De: datanom.net m...@datanom.net À: pve-devel pve-devel@pve.proxmox.com Envoyé: Mardi 13 Janvier 2015 18:35:23 Objet: Re: [pve-devel] spice: problems when installing new certificate On Mon, 12 Jan 2015 01:59:22 +0100 Michael Rasmussen m...@datanom.net wrote: I have an idea that the migration of the spiceproxy has something to do with it. What exactly does a migration of the spiceproxy which is not done by restarting the spiceproxy? Nobody observed this? -- Hilsen/Regards Michael Rasmussen Get my public GnuPG keys: michael at rasmussen dot cc http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0xD3C9A00E mir at datanom dot net http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0xE501F51C mir at miras dot org http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0xE3E80917 -- /usr/games/fortune -es says: It's not reality or how you perceive things that's important -- it's what you're taking for it... ___ pve-devel mailing list pve-devel@pve.proxmox.com http://pve.proxmox.com/cgi-bin/mailman/listinfo/pve-devel ___ pve-devel mailing list pve-devel@pve.proxmox.com http://pve.proxmox.com/cgi-bin/mailman/listinfo/pve-devel
Re: [pve-devel] spice: problems when installing new certificate
On Mon, 12 Jan 2015 01:49:36 +0100 Michael Rasmussen m...@datanom.net wrote: but to no vain. Since I was out of any more ideas I migrated all VM's and CT's from one node at restarted the node and low and behold after restart of only one node everything work again!! I have an idea that the migration of the spiceproxy has something to do with it. What exactly does a migration of the spiceproxy which is not done by restarting the spiceproxy? -- Hilsen/Regards Michael Rasmussen Get my public GnuPG keys: michael at rasmussen dot cc http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0xD3C9A00E mir at datanom dot net http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0xE501F51C mir at miras dot org http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0xE3E80917 -- /usr/games/fortune -es says: If rash develops, discontinue use. pgpVea66IYksB.pgp Description: OpenPGP digital signature ___ pve-devel mailing list pve-devel@pve.proxmox.com http://pve.proxmox.com/cgi-bin/mailman/listinfo/pve-devel
[pve-devel] spice: problems when installing new certificate
Hi all, I had to change my certificate this week-end since it had expired. Installing new certificate like I have wrote in the wiki (intermediate certificate) but spice refused to validate the new certificate. I try all combinations of restarting the following: pve-cluster pvedaemon pveproxy spiceproxy but to no vain. Since I was out of any more ideas I migrated all VM's and CT's from one node at restarted the node and low and behold after restart of only one node everything work again!! My question is therefore: Which daemons needs to be restarted after changing certificate? I had hoped changing certificate could be done without having to restart a node. -- Hilsen/Regards Michael Rasmussen Get my public GnuPG keys: michael at rasmussen dot cc http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0xD3C9A00E mir at datanom dot net http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0xE501F51C mir at miras dot org http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0xE3E80917 -- /usr/games/fortune -es says: Sorry, no fortune this time. pgpPs7zO_4nEp.pgp Description: OpenPGP digital signature ___ pve-devel mailing list pve-devel@pve.proxmox.com http://pve.proxmox.com/cgi-bin/mailman/listinfo/pve-devel