[libvirt-users] libvirt tls error

Daniel P. Berrange berrange at redhat.com
Mon Jun 3 10:34:13 UTC 2013


On Tue, May 28, 2013 at 05:00:05PM +0200, Francesco wrote:
> On Mon, Apr 22, 2013 at 12:03:43PM +0800, yue wrote:
> > centos6.3,libvirt 0.9.10.
> > [root at ovirtdev private]# virsh -c qemu+tls://ovirtdev.localhost/system list
> > 2013-04-22 03:37:09.362+0000: 9898: info : libvirt version: 0.9.10, package: 21.el6_3.8 (CentOS BuildSystem <http://bugs.centos.org>, 2013-01-28-19:24:16, c6b10.bsys.dev.centos.org)
> > 2013-04-22 03:37:09.362+0000: 9898: warning : virNetClientIncomingEvent:1665 : Something went wrong during async message processing
> > error: Unable to read TLS confirmation: Input/output error
> > error: failed to connect to the hypervisor
> >  
> > thanks
> 
> I get a very similar error with an updated Centos 6.4 distro:
> 
> [root at darkgoo ~]# virsh -c qemu+tls://hvmsrv03/system

> [session] owner does not match the hostname hvmsrv03
> error: failed to connect to the hypervisor error: authentication failed: Failed to verify peer's certificate

This indicates the problem. The hostname you have used when creating the
certificate does not match the hostname in the libvirt URI (hvmsrv03).
Presumably the certificate has the fully qualified hostname


Daniel
-- 
|: http://berrange.com      -o-    http://www.flickr.com/photos/dberrange/ :|
|: http://libvirt.org              -o-             http://virt-manager.org :|
|: http://autobuild.org       -o-         http://search.cpan.org/~danberr/ :|
|: http://entangle-photo.org       -o-       http://live.gnome.org/gtk-vnc :|




More information about the libvirt-users mailing list