[ovirt-users] Re: Extend apache.cer and websocket-proxy.cer

2023-11-04 Thread LS CHENG
Hi again Forgot to mention that I am using self signed certificates Thank you On Sat, Nov 4, 2023 at 2:07 PM LS CHENG wrote: > Hi all > > I am running Oracle Linux Virtualization Manager 4.4. > > The default expiration length for apache.cer and websocket-proxy.cer is 1 > year, is there a way

[ovirt-users] Re: Extend apache.cer and websocket-proxy.cer

2023-11-04 Thread LS CHENG
Hi Yes it is generated with engine-setup. How do you extend the certificate validation value in engine-setup? (I am aware that browser can have problems with long duration certificates as explained in https://techbeacon.com/security/google-apple-mozilla-enforce-1-year-max-security-certifications

[ovirt-users] Re: Extend apache.cer and websocket-proxy.cer

2023-11-04 Thread LS CHENG
Hi I think I will stick with the default certificate 398 days rule. To renew the certificate automatically I am thinking to write a script and run engine-setup which will detect the certificate are close to expire such as following * --== PKI CONFIGURATION ==-- One

[ovirt-users] Re: Extend apache.cer and websocket-proxy.cer

2023-11-20 Thread Matej Dujava via Users
Hi, > certificate validation value in engine-setup Do you mean expiration date on CA generated by ovirt? Then I would look at (copied from bugzila): > I found two places where the lifspan is hard coded in scripts: > /usr/share/ovirt-engine/bin/pki-enroll-openssh-cert.sh > /usr/share/ovirt-engine