Re: Secure Live Migration for KVM

2021-03-16 Thread Rohit Yadav
ohit Yadav From: Sean Lair Sent: Tuesday, March 16, 2021 2:43:24 AM To: dev@cloudstack.apache.org Subject: RE: Secure Live Migration for KVM Quick update so no one spends any time looking into this. Found a few things that we are working to fix: 1. if ca.plugin.root.auth.strictn

RE: Secure Live Migration for KVM

2021-03-15 Thread Sean Lair
, March 15, 2021 12:18 PM To: dev@cloudstack.apache.org Subject: RE: Secure Live Migration for KVM Hi Rohit from our initial debugging, the issue may be a little more involved. Maybe you could add some insight. We added some debug logging to monitor the size of the activeCertMap and have noti

RE: Secure Live Migration for KVM

2021-03-15 Thread Sean Lair
an -Original Message- From: Rohit Yadav Sent: Friday, March 12, 2021 12:50 AM To: dev@cloudstack.apache.org Subject: [DKIM Fail] Re: Secure Live Migration for KVM Hi Greg, I think you're right the https://github.com/apache/cloudstack/pull/4156 should fix the auto-renewal is

Re: Secure Live Migration for KVM

2021-03-11 Thread Rohit Yadav
riday, March 12, 2021 04:00 To: dev@cloudstack.apache.org Subject: Re: Secure Live Migration for KVM Further investigation finds this PR which may be related - https://github.com/apache/cloudstack/pull/4156. We are investigating if this could be the cause. -- Greg Goodrich | IP Pathways Develo

Re: Secure Live Migration for KVM

2021-03-11 Thread Greg Goodrich
Further investigation finds this PR which may be related - https://github.com/apache/cloudstack/pull/4156. We are investigating if this could be the cause. -- Greg Goodrich | IP Pathways Development Manager 3600 109th Street | Urbandale, IA 50322 p. 515.422.9346 | e. ggoodr...@ippathways.com

Secure Live Migration for KVM

2021-03-11 Thread Greg Goodrich
We have just discovered in our Lab environment that the certificates for libvirtd did not auto renew. Thus when we did an update, and restart of the agent, it failed to start, due to Libvirtd failing to start from an expired certificate. We then checked our production hosts, and their certificat