[ovirt-users] Re: Support for Shared SAS storage

2020-08-08 Thread Lao Dh via Users
 Jeff. Your answer inspire me. I'm going to try it again. :)

2020年8月8日土曜日 12:31:16 GMT+8、Vinícius Ferrão via Users 
が書いたメール:  
 
 Really??
Treat it as FC??
Thats new for me.


On 8 Aug 2020, at 00:35, Jeff Bailey  wrote:

I haven't tried with 4.4 but shared SAS works just fine with 4.3 (and has for 
many, many years).  You simply treat it as Fibre Channel.  If your LUNs aren't 
showing up I'd make sure they're being claimed as multipath devices.  You want 
them to be.  After that, just make sure they're sufficiently wiped so they 
don't look like they're in use.



On 8/7/2020 10:49 PM, Lao Dh via Users wrote:

Wow. That's sound bad. Then what storage type you choose at last (with your SAS 
connected storage)? VMware vSphere support DAS. Red Hat should do something.

2020年8月8日土曜日 4:06:34 GMT+8、Vinícius Ferrão via Users が書いたメール: 

No, there’s no support for direct attached shared SAS storage on oVirt/RHV.

Fibre Channel is a different thing that oVirt/RHV supports.

> On 7 Aug 2020, at 08:52, hkexdong--- via Users  wrote:
> 
> Hello Vinícius,
> Do you able to connect the SAS external storage?
> Now I've the problem during host engine setup. Select Fibre Channel and end 
> up show "No LUNS found".
> ___
> Users mailing list -- users@ovirt.org
> To unsubscribe send an email to users-le...@ovirt.org
> Privacy Statement: https://www.ovirt.org/privacy-policy.html
> oVirt Code of Conduct: 
> https://www.ovirt.org/community/about/community-guidelines/
> List Archives: 
> https://lists.ovirt.org/archives/list/users@ovirt.org/message/RDPLKGIRN5ZGIEPWGOKMGNFZNMCEN5RC/

___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/2CLI3YSYU7BPI62YANJXZV7RIQFOXXED/

___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/WOBHQDCBZZK5WKRAUNHP5CGFYY3HQYYU/

___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/UY52JRY5EMQJTMKG3POE2YXSFGL7P55S/


___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/275GTMI6XQKR52U32WPESHA4BPSAHWZF/
  ___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/5BGA2FCDFSUZQ26YSPWD62MCMSYGXRIZ/


[ovirt-users] Re: [rhev-tech] ovirt-imageio-proxy not working after updating SSL certificates with a wildcard cert issued by AlphaSSL (intermediate)

2020-08-08 Thread Nir Soffer
On Mon, Jul 27, 2020 at 6:40 PM Nir Soffer  wrote:

> On Sat, Jul 25, 2020 at 5:24 AM Lynn Dixon  wrote:
>
>> All,
>> I recently bought a wildcard certificate for my lab domain (shadowman.dev)
>> and I replaced all the certs on my RHV4.3 machine per our documentation.
>> The WebUI presents the certs successfully and without any issues, and
>> everything seemed to be fine, until I tried to upload a disk image (or an
>> ISO) to my storage domain.  I get this error in the events tab:
>>
>> https://share.getcloudapp.com/p9uPvegx
>> [image: image.png]
>>
>> I also see that the disk is showing up in my storage domain, but its
>> showing "Paused by System" and I can't do anything with it.  I cant even
>> delete it!
>>
>> I have tried following this document to fix the issue, but it didn't
>> work: https://access.redhat.com/solutions/4148361
>>
>> I am seeing this error pop into my engine.log:
>> https://pastebin.com/kDLSEq1A
>>
>> And I see this error in my image-proxy.log:
>> WARNING 2020-07-24 15:26:34,802 web:137:web:(log_error) ERROR
>> [172.17.0.30] PUT /tickets/ [403] Error verifying signed ticket: Invalid
>> ovirt ticket (data='--my_ticket_data-', reason=Untrusted
>> certificate) [request=0.002946/1]
>>
>
> This means ssl_* configuration in broken.
>
> We have 2 groups:
>
> Client ssl configuration:
>
> # Key file for SSL connections
> ssl_key_file = /etc/pki/ovirt-engine/keys/image-proxy.key.nopass
>
> # Certificate file for SSL connections
> ssl_cert_file = /etc/pki/ovirt-engine/certs/image-proxy.cer
>
> And engine SSL configuration:
>
> # Certificate file used when decoding signed token
> engine_cert_file = /etc/pki/ovirt-engine/certs/engine.cer
>
> # CA certificate file used to verify signed token
> engine_ca_cert_file = /etc/pki/ovirt-engine/ca.pem
>
> engine configuration is used to verify signed ticket used by engine when
> adding tickets to the proxy. This is internal flow that clients should not
> care
> about. You should not replace these unless you are using also custom
> certificate
> for engine itself - very unlikely and maybe unsupported.
> (Didi please correct me on this).
>
> SSL client configuration is used when communicating with clients, and does
> not depend on engine ssl configuration. You can replace these with your
> certificates.
>
> Can you share your /etc/ovirt-imageio/ovirt-imageio-proxy.conf?
>
> The main issue with the current configuration is that we don't have
> ssl_ca_cert configuration,
> assuming that ssl_cert_file is a self signed certificate that includes the
> CA certificate, since
> this is what engine is creating.
>
> In 4.4, we have more flexible configuration that should work for your case:
>
> $ cat /etc/ovirt-imageio/conf.d/50-engine.conf
> ...
> [tls]
> enable = true
> key_file = /etc/pki/ovirt-engine/keys/apache.key.nopass
> cert_file = /etc/pki/ovirt-engine/certs/apache.cer
> ca_file = /etc/pki/ovirt-engine/apache-ca.pem
>
> Adding ssl_ca_cert to imageio 1.5.3 looks simple enough, so I posted this
> completely untested patch:
> https://gerrit.ovirt.org/c/110498/
>
> You can try to upgrade your proxy to using this build:
>
> https://jenkins.ovirt.org/job/ovirt-imageio_standard-check-patch/3384/artifact/build-artifacts.el7.x86_64/
>
> Add a yum repo file with this baseurl=.
>
> Again this is untested, but you seem to be in the best place to test it,
> since I don't have any real certificates for testing.
>
> It would also be useful if you file a bug for this issue.
>

Lynn, did you resolve this issue?


>
> Nir
>
> Now, when I bought my wildcard, I was given a root certificate for the CA,
>> as well as a separate intermediate CA certificate from the provider.
>> Likewise, they gave me a certificate and a private key of course. The root
>> and intermediate CA's certificates have been added
>> to /etc/pki/ca-trust/source/anchors/ and I did an update-ca-trust.
>>
>> I also started experiencing issues with the ovpn network provider at the
>> same time I replaced the SSL certs, but I disregarded it at the time, but
>> now I am thinking its related.  Any advice on what to look for to fix the
>> ovirt-imageio-proxy?
>>
>> Thanks!
>>
>>
>> *Lynn Dixon* | Red Hat Certified Architect #100-006-188
>> *Solutions Architect* | NA Commercial
>> Google Voice: 423-618-1414
>> Cell/Text: 423-774-3188
>> Click here to view my Certification Portfolio 
>>
>>
>>
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/RITYEGP7J3BO2IMIQ7YEXZWV3STKEXLF/


[ovirt-users] Re: oVirt Node 4.1.1 Hosted Engine Deployment Fibre Channel No LUNS found

2020-08-08 Thread Strahil Nikolov via Users
Not when both client and server is the same node and you use 
"localhost:/nfs-share"

Best Regards,
Strahil Nikolov






В събота, 8 август 2020 г., 05:56:10 Гринуич+3, Lao Dh  
написа: 







NFS utilize the network adapter, am I right? The LAN port max speed on the 
storage is just 100Mb/s. That's too slow for hosting VMs.

Regards,
Jeremy




2020年8月8日土曜日 2:15:08 GMT+8、Strahil Nikolov via Users が書いたメール: 





Do  you have the option for POSIX compliant FS ?
If not,  I guess the simplest way is to setup NFS export that to be used for 
the engine.

Best  Regards,
Strahil Nikolov

На 7 август 2020 г. 15:59:55 GMT+03:00, Lao Dh via Users  
написа:
>Hello Strahil,I follow the guide in "Installing oVirt as a self-hosted
>engine using the Cockpit web interface". Only 1 host and 1 SAS storage.
>Host and storage are direct attached. CentOS 8 was installed in host
>local disk.Only 1 SAS cable connected. So I think shouldn't be the
>issue of Multipath.
>
>Regards,Jeremy
>
>
>
>
>
>2020年8月7日金曜日 20:37:47 GMT+8、Strahil Nikolov
>が書いたメール:  
> 
> Are you using the single-node wizard  ?
>
>Best Regards,
>Strahil Nikolov
>
>На 7 август 2020 г. 11:34:52 GMT+03:00, hkexdong--- via Users
> написа:
>>I've an external RAID subsystem connect to the host by SAS cable
>>(SFF-8644).
>>I follow the instructions of the RAID card manufacture. Include the
>>driver during host installation. And I can see the created RAID
>volumes
>>(LUNs) available in "Installation Destination". Although I choose to
>>install the engine in host local disk.
>>The installation success and I proceed to hosted engine deployment by
>>Cockpit. And now I stuck at part 4 Storage.
>>I believe "Storage Type" select "Fibre Channel" is correct even I'm
>not
>>using fibre cable. As NFS and iSCSI are utilize network.
>>I confirm there are 2 RAID volume (LUN0 & LUN1) created in the
>external
>>RAID subsystem. Why oVirt cannot discover them. What could be wrong :(
>>___
>>Users mailing list -- users@ovirt.org
>>To unsubscribe send an email to users-le...@ovirt.org
>>Privacy Statement: https://www.ovirt.org/privacy-policy.html
>>oVirt Code of Conduct:
>>https://www.ovirt.org/community/about/community-guidelines/
>>List Archives:
>>https://lists.ovirt.org/archives/list/users@ovirt.org/message/IIMW6VBS4JBL5WJFTS7AWDS5ENQDB63Y/
> 
___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/5WYU5SRXKGYDTTLA5WOMYZQULXP4OGLN/


___
Users mailing list -- users@ovirt.org
To unsubscribe send an email to users-le...@ovirt.org
Privacy Statement: https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct: 
https://www.ovirt.org/community/about/community-guidelines/
List Archives: 
https://lists.ovirt.org/archives/list/users@ovirt.org/message/ZJMQOJLFRMQTN6DCESUYALRXKLZWG74R/