apache / apache/cloudstack

VM console cannot access after VNC certificate expired

Open
#9,718 17 comments 0 reactions 0 assignees View on GitHub
component:ca component:console-proxy type:improvement
Dominant language
Java
Stars
3.1k
Forks
1.4k
Avg merge
6d 19h
Merged PRs (30d)
32

Description

##### ISSUE TYPE

* Bug Report

##### COMPONENT NAME

~~~
CPVM
~~~

##### CLOUDSTACK VERSION

~~~
4.18
~~~

##### CONFIGURATION

advanced networking

##### OS / ENVIRONMENT

Hypervisro: KVM virtualization with ubuntu 22.04

##### SUMMARY

VM console cannot access after VNC certificate expired。
Default certificate valid for 1 year ,then automatically renews certificates when they expire by cloudstack。
I made sure the certificate was updated on the host,but Th running VM instances need stop and start to apply the new certificate or migraton to other host. For production environments, this is hard to do

I don't know how to get a new certificate to take effect without rebooting the vm

https://github.com/apache/cloudstack/pull/7015

##### STEPS TO REPRODUCE

~~~

~~~

##### EXPECTED RESULTS

~~~
Make a new certificate to take effect without rebooting the vm
Provide a setting to turn off tls for vnc
~~~

##### ACTUAL RESULTS

~~~

~~~

Contributor guide

Open the contributing guide

Research direction

Start with the CPVM and VNC certificate renewal flow described in the issue, then review the linked pull request #7015 and the recent discussion. Reproduce the expired-certificate case on CloudStack 4.18 with KVM and Ubuntu 22.04; done means a renewed certificate applies to running VMs without stopping, starting, or migrating them.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, ubuntu
Domain
cloud, infrastructure
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.