Re: [Users] NAT configuration

2014-02-07 Thread Douglas Schilling Landgraf

On 02/07/2014 03:53 PM, martin.tru...@cspq.gouv.qc.ca wrote:

No, it does not work indeed.

I cannot find the username in step 3.
I found the password in Step 4: shibboleth.


Try username: vdsm@ovirt



On step 18 it does not work because I cannot access the posgresql database.


You could do:

# vi /var/lib/pgsql/data/pg_hba.conf
local   allpostgres trust

- Restart postgresql

Please let us know if it works.

Thanks!




-Message d'origine-
De : Itamar Heim [mailto:ih...@redhat.com]
Envoyé : 5 février 2014 01:50
À : Trudel, Martin (CELL); users@ovirt.org
Objet : Re: [Users] NAT configuration

On 02/04/2014 09:20 PM, martin.tru...@cspq.gouv.qc.ca wrote:

Hi,

I want to configure NAT in Ovirt with this procedure :
*http://lists.ovirt.org/pipermail/users/2012-April/001751.html

But *I *don*'t have the login password of virsh and for the PosgreSQL
database.

I used the last version of oVirt with default installation with
engine-setup


the steps described don't work for you as is?
(step 6 explains where the user/password for libvirt/virsh are. the db part 
should just work as-is if you are using root (at least it used to)



Thanks.
**
--
-- Ce message est confidentiel et est à l'usage exclusif du
destinataire identifié ci-dessus. Toute autre personne est, par les
présentes, avisée qu'il lui est strictement interdit de le diffuser,
de le distribuer, d'en dévoiler le contenu ou de le reproduire. Si
vous avez reçu cette communication par erreur, veuillez en informer
l'expéditeur par courrier électronique immédiatement et détruire
l'original de ce message ainsi que toute copie.
--
--


___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users



___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users




--
Cheers
Douglas
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [Users] NAT configuration

2014-02-07 Thread Itamar Heim

On 02/07/2014 10:56 PM, martin.tru...@cspq.gouv.qc.ca wrote:

Can you tell me the procedure to install and configure the vdsm-hook-extnet ?


for general hook information:
http://www.ovirt.org/VDSM-Hooks
http://www.ovirt.org/VDSM-Hooks_Catalogue

for this specific hook:
http://gerrit.ovirt.org/gitweb?p=vdsm.git;a=blob;f=vdsm_hooks/extnet/README;h=0778dbb3ef85c5ae179fb0f6c9ceeabc268abe89;hb=HEAD



-Message d'origine-
De : Dan Kenigsberg [mailto:dan...@redhat.com]
Envoyé : 5 février 2014 08:02
À : Trudel, Martin (CELL)
Cc : users@ovirt.org
Objet : Re: [Users] NAT configuration

On Tue, Feb 04, 2014 at 08:20:26PM +, martin.tru...@cspq.gouv.qc.ca wrote:

Hi,

I want to configure NAT in Ovirt with this procedure :
http://lists.ovirt.org/pipermail/users/2012-April/001751.html

But I don't have the login password of virsh and for the PosgreSQL database.

I used the last version of oVirt with default installation with
engine-setup


Note that now it is possible to use vdsm-hook-extnet instead of changing 
Engine's database (step 12 and forth). You do not have your NAT network defined 
in oVirt, but you can define a vNIC Profile with the property
extnet=natbr0 and whatever network you have defined (say ovirtmgmt).

When you attach a vnic of a VM to your vNIC profile and start the VM, the hook 
script kicks into action and points the vnic to natbr0.

Dan.

  Ce message est confidentiel et est à l'usage exclusif du destinataire 
identifié ci-dessus. Toute autre personne est, par les présentes, avisée qu'il 
lui est strictement interdit de le diffuser, de le distribuer, d'en dévoiler le 
contenu ou de le reproduire. Si vous avez reçu cette communication par erreur, 
veuillez en informer l'expéditeur par courrier électronique immédiatement et 
détruire l'original de ce message ainsi que toute copie.

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users



___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [Users] NAT configuration

2014-02-05 Thread Sven Kieske
It's actually step 5 :)

Am 05.02.2014 07:50, schrieb Itamar Heim:
 (step 6 explains where the user/password for libvirt/virsh are.

-- 
Mit freundlichen Grüßen / Regards

Sven Kieske

Systemadministrator
Mittwald CM Service GmbH  Co. KG
Königsberger Straße 6
32339 Espelkamp
T: +49-5772-293-100
F: +49-5772-293-333
https://www.mittwald.de
Geschäftsführer: Robert Meyer
St.Nr.: 331/5721/1033, USt-IdNr.: DE814773217, HRA 6640, AG Bad Oeynhausen
Komplementärin: Robert Meyer Verwaltungs GmbH, HRB 13260, AG Bad Oeynhausen
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [Users] NAT configuration

2014-02-05 Thread Sven Kieske
Well, I just tested this.
and I can't connect to virsh with this information.
I guess the mentioned user vdsm@rhevh might not be the actual one
used in 3.3.2 anymore? (mail is from 2012 and mentions rhev, so..)

or can't libvirt manage multiple authenticated users?
Because I registered my own using:

saslpasswd2 -a libvirt USERNAME

which still works.

Am 05.02.2014 09:15, schrieb Sven Kieske:
 It's actually step 5 :)
 
 Am 05.02.2014 07:50, schrieb Itamar Heim:
 (step 6 explains where the user/password for libvirt/virsh are.
 

-- 
Mit freundlichen Grüßen / Regards

Sven Kieske

Systemadministrator
Mittwald CM Service GmbH  Co. KG
Königsberger Straße 6
32339 Espelkamp
T: +49-5772-293-100
F: +49-5772-293-333
https://www.mittwald.de
Geschäftsführer: Robert Meyer
St.Nr.: 331/5721/1033, USt-IdNr.: DE814773217, HRA 6640, AG Bad Oeynhausen
Komplementärin: Robert Meyer Verwaltungs GmbH, HRB 13260, AG Bad Oeynhausen
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [Users] NAT configuration

2014-02-05 Thread Joop

On 5-2-2014 9:27, Sven Kieske wrote:

Well, I just tested this.
and I can't connect to virsh with this information.
I guess the mentioned user vdsm@rhevh might not be the actual one
used in 3.3.2 anymore? (mail is from 2012 and mentions rhev, so..)



vdsm@ovirt seems to work :-)

Joop

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [Users] NAT configuration

2014-02-05 Thread Sven Kieske
I can confirm that vdsm@ovirt does work.

However, I have the strong feeling that
the password in /etc/pki/vdsm/keys/libvirt_password
is static for all installations.

And gerrit proves me right:

http://gerrit.ovirt.org/gitweb?p=vdsm.git;a=blob;f=vdsm/libvirt_password;h=09e60bce9bc401bb8943154f7cb9cb08bd0f49da;hb=refs/heads/master

So what is the purpose of authentication when that information
is public?

I created a BZ for this:

https://bugzilla.redhat.com/show_bug.cgi?id=1061639

PS: I hope, whoever coded this, feels a little bit ashamed
and perhaps buys a good book on writing secure code and reads it..

Am 05.02.2014 09:55, schrieb Joop:
 On 5-2-2014 9:27, Sven Kieske wrote:
 Well, I just tested this.
 and I can't connect to virsh with this information.
 I guess the mentioned user vdsm@rhevh might not be the actual one
 used in 3.3.2 anymore? (mail is from 2012 and mentions rhev, so..)


 vdsm@ovirt seems to work :-)
 
 Joop


-- 
Mit freundlichen Grüßen / Regards

Sven Kieske

Systemadministrator
Mittwald CM Service GmbH  Co. KG
Königsberger Straße 6
32339 Espelkamp
T: +49-5772-293-100
F: +49-5772-293-333
https://www.mittwald.de
Geschäftsführer: Robert Meyer
St.Nr.: 331/5721/1033, USt-IdNr.: DE814773217, HRA 6640, AG Bad Oeynhausen
Komplementärin: Robert Meyer Verwaltungs GmbH, HRB 13260, AG Bad Oeynhausen
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [Users] NAT configuration

2014-02-05 Thread Dan Kenigsberg
On Wed, Feb 05, 2014 at 09:50:04AM +, Sven Kieske wrote:
 I can confirm that vdsm@ovirt does work.
 
 However, I have the strong feeling that
 the password in /etc/pki/vdsm/keys/libvirt_password
 is static for all installations.
 
 And gerrit proves me right:
 
 http://gerrit.ovirt.org/gitweb?p=vdsm.git;a=blob;f=vdsm/libvirt_password;h=09e60bce9bc401bb8943154f7cb9cb08bd0f49da;hb=refs/heads/master
 
 So what is the purpose of authentication when that information
 is public?
 
 I created a BZ for this:
 
 https://bugzilla.redhat.com/show_bug.cgi?id=1061639
 
 PS: I hope, whoever coded this, feels a little bit ashamed
 and perhaps buys a good book on writing secure code and reads it..

I feel ashamed, but not due to the security issue here.

Vdsm uses a unix domain socket to connect to libvirtd. That socket is
owned by vdsm, so that only vdsm and root can use it. There is no
security reason to use a password at all.

I am ashamed for caving in and adding an obfuscation layer, designed
only to deter local administrators from messing with libvirt under the
feet of ovirt. This little hurdle does not deter from messing with qemu
directly, but I suppose that qemu's command line does a good job anyway.

Red Hat support folks repeatedly claim that this hurdle is more
effective than putting a release note warning of the dangers in direct
libvirt access.

Dan.


___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [Users] NAT configuration

2014-02-05 Thread Dan Kenigsberg
On Tue, Feb 04, 2014 at 08:20:26PM +, martin.tru...@cspq.gouv.qc.ca wrote:
 Hi,
 
 I want to configure NAT in Ovirt with this procedure :
 http://lists.ovirt.org/pipermail/users/2012-April/001751.html
 
 But I don't have the login password of virsh and for the PosgreSQL database.
 
 I used the last version of oVirt with default installation with engine-setup

Note that now it is possible to use vdsm-hook-extnet instead of changing
Engine's database (step 12 and forth). You do not have your NAT network
defined in oVirt, but you can define a vNIC Profile with the property
extnet=natbr0 and whatever network you have defined (say ovirtmgmt).

When you attach a vnic of a VM to your vNIC profile and start the
VM, the hook script kicks into action and points the vnic to natbr0.

Dan.
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [Users] NAT configuration

2014-02-05 Thread Sven Kieske
Well I didn't know the exact background for this code
and I can understand it from a management perspective, but from
a sysadmin perspective it is useless (it does not prevent anything
against an informed attacker) and may be even lead to false security
assumptions (nobody can mess with libvirt, it's all authenticated).

But thanks for pointing out the reasoning behind this, I still don't
like it, but I can understand it.

(Funny side fact: the very first thing we did, when we found that
libvirt just allows authenticated access was to find out how to
create our own user, and every admin asks at first: how can I access
libvirt, when something goes wrong?)


Am 05.02.2014 13:45, schrieb Dan Kenigsberg:
 On Wed, Feb 05, 2014 at 09:50:04AM +, Sven Kieske wrote:
 I can confirm that vdsm@ovirt does work.

 However, I have the strong feeling that
 the password in /etc/pki/vdsm/keys/libvirt_password
 is static for all installations.

 And gerrit proves me right:

 http://gerrit.ovirt.org/gitweb?p=vdsm.git;a=blob;f=vdsm/libvirt_password;h=09e60bce9bc401bb8943154f7cb9cb08bd0f49da;hb=refs/heads/master

 So what is the purpose of authentication when that information
 is public?

 I created a BZ for this:

 https://bugzilla.redhat.com/show_bug.cgi?id=1061639

 PS: I hope, whoever coded this, feels a little bit ashamed
 and perhaps buys a good book on writing secure code and reads it..
 
 I feel ashamed, but not due to the security issue here.
 
 Vdsm uses a unix domain socket to connect to libvirtd. That socket is
 owned by vdsm, so that only vdsm and root can use it. There is no
 security reason to use a password at all.
 
 I am ashamed for caving in and adding an obfuscation layer, designed
 only to deter local administrators from messing with libvirt under the
 feet of ovirt. This little hurdle does not deter from messing with qemu
 directly, but I suppose that qemu's command line does a good job anyway.
 
 Red Hat support folks repeatedly claim that this hurdle is more
 effective than putting a release note warning of the dangers in direct
 libvirt access.
 
 Dan.
 
 
 
 
 

-- 
Mit freundlichen Grüßen / Regards

Sven Kieske

Systemadministrator
Mittwald CM Service GmbH  Co. KG
Königsberger Straße 6
32339 Espelkamp
T: +49-5772-293-100
F: +49-5772-293-333
https://www.mittwald.de
Geschäftsführer: Robert Meyer
St.Nr.: 331/5721/1033, USt-IdNr.: DE814773217, HRA 6640, AG Bad Oeynhausen
Komplementärin: Robert Meyer Verwaltungs GmbH, HRB 13260, AG Bad Oeynhausen
___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


[Users] NAT configuration

2014-02-04 Thread martin.trudel
Hi,

I want to configure NAT in Ovirt with this procedure :
http://lists.ovirt.org/pipermail/users/2012-April/001751.html

But I don't have the login password of virsh and for the PosgreSQL database.

I used the last version of oVirt with default installation with engine-setup

Thanks.

Ce message est confidentiel et est à l'usage exclusif du destinataire identifié 
ci-dessus. Toute autre personne est, par les présentes, avisée qu'il lui est 
strictement interdit de le diffuser, de le distribuer, d'en dévoiler le contenu 
ou de le reproduire. Si vous avez reçu cette communication par erreur, veuillez 
en informer l'expéditeur par courrier électronique immédiatement et détruire 
l'original de ce message ainsi que toute copie.

___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users


Re: [Users] NAT configuration

2014-02-04 Thread Itamar Heim

On 02/04/2014 09:20 PM, martin.tru...@cspq.gouv.qc.ca wrote:

Hi,

I want to configure NAT in Ovirt with this procedure :
*http://lists.ovirt.org/pipermail/users/2012-April/001751.html

But *I *don*'t have the login password of virsh and for the PosgreSQL
database.

I used the last version of oVirt with default installation with engine-setup


the steps described don't work for you as is?
(step 6 explains where the user/password for libvirt/virsh are. the db 
part should just work as-is if you are using root (at least it used to)




Thanks.
**

Ce message est confidentiel et est à l'usage exclusif du destinataire
identifié ci-dessus. Toute autre personne est, par les présentes, avisée
qu'il lui est strictement interdit de le diffuser, de le distribuer,
d'en dévoiler le contenu ou de le reproduire. Si vous avez reçu cette
communication par erreur, veuillez en informer l'expéditeur par courrier
électronique immédiatement et détruire l'original de ce message ainsi
que toute copie.



___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users



___
Users mailing list
Users@ovirt.org
http://lists.ovirt.org/mailman/listinfo/users