Re: [ovirt-users] Regenerating new SSL certificates for ovirt-engine

2014-04-10 Thread Trey Dockendorf
e.key.nopass > > And restart apache. > > Regards, > Alon > > ----- Original Message - >> From: "Sven Kieske" >> To: users@ovirt.org >> Sent: Thursday, April 10, 2014 12:41:17 PM >> Subject: Re: [ovirt-users] Regenerating new SSL certificat

Re: [ovirt-users] Regenerating new SSL certificates for ovirt-engine

2014-04-10 Thread Alon Bar-Lev
ot; > To: users@ovirt.org > Sent: Thursday, April 10, 2014 12:41:17 PM > Subject: Re: [ovirt-users] Regenerating new SSL certificates for ovirt-engine > > Hi, > > as a first step, make sure to read and understand this page: > http://www.ovirt.org/Features/PKI > > There

Re: [ovirt-users] Regenerating new SSL certificates for ovirt-engine

2014-04-10 Thread Sven Kieske
Hi, as a first step, make sure to read and understand this page: http://www.ovirt.org/Features/PKI There are different certificates for different things. I have sadly no time to elaborate on this difficult topic. But you may want restrict the access to your engine from the network side (firewal

[ovirt-users] Regenerating new SSL certificates for ovirt-engine

2014-04-09 Thread Trey Dockendorf
Given the recent OpenSSL heartbleed vulnerability, I would like to regenerate the certificates used by my ovirt-engine server. What are the steps to regenerate the certificates, and which certificates should be regenerated? My ovirt-engine host is on our campus LAN, which offers no real protectio