GitHub user Flpvoigt added a comment to the discussion: HTTPS Does Not Work For 
Management Server

CloudStack's embedded Jetty can terminate HTTPS directly, so HAProxy is 
optional. The first thing I would verify is that the settings are in the active 
file, /etc/cloudstack/management/server.properties, without a second 
conflicting entry:

~~~
https.enable=true
https.port=8443
https.keystore=/etc/cloudstack/management/cloud.jks
https.keystore.password=<the-keystore-password>
~~~

A few checks are important:

- Confirm the keystore contains a private-key entry, not only a trusted 
certificate: keytool -list -v -keystore /etc/cloudstack/management/cloud.jks.
- Make sure the keystore and every parent directory are readable/traversable by 
the account running cloudstack-management (changing only the file ownership may 
not be enough).
- Confirm the certificate SAN contains the hostname used in the browser, and 
that the keystore contains the full certificate chain.
- Restart the service and check the first startup lines in 
/var/log/cloudstack/management/management-server.log. They should show 
https.enable=true and https.port=8443. If the log still says 
https.enable=false, CloudStack is not reading the settings you edited.
- Test the endpoint directly with curl -vk 
https://<management-host>:8443/client and verify that TCP/8443 is allowed 
between your browser and the management server.

The official configuration uses these same server.properties keys and requires 
the keystore to exist and be readable by the management server: 
https://docs.cloudstack.apache.org/en/4.20.1.0/installguide/optional_installation.html

If it still starts only on HTTP, please paste the startup line containing 
http.enable/https.enable and the output of keytool -list with passwords and 
private details redacted.

GitHub link: 
https://github.com/apache/cloudstack/discussions/13417#discussioncomment-18704886

----
This is an automatically sent email for [email protected].
To unsubscribe, please send an email to: [email protected]

Reply via email to