Foreman Certificate Issues

Hi,

I'm having two problems with Foreman and registering new hosts. I don't
know if they are related.

Basically after installing foreman 1.14 on Centos 7.3 and adding the FQDN
to my pc with the internal IP in my /etc/hosts file I can access the
https:// website but it's giving me an SSL error.

The second problem I'm experiencing is when I'm registering new hosts to my
Katello server. I'm getting this error message. 'Unable to verify server's
identity: certificate verify failed'

This is the command i'm using. subscription-manager register
–org="Default_Organization" --activationkey="Operations_Non-Prod"

It would seem that I'm not able to register new hosts because of the https
error I'm getting when I'm accessing the web interface. I did use the
foreman-installer which created the SSL cert for me.

I did disable SSL checking on the hosts after which I could get it
registered to Foreman. But when I then push new repositories and try to
update, it is also giving SSL cert errors for the repos.

Anyone experience something like this? Or did I mess up somewhere?

Asjas schrieb:

> Basically after installing foreman 1.14 on Centos 7.3 and adding the
> FQDN to my pc with the internal IP in my /etc/hosts file I can access
> the https:// website but it's giving me an SSL error.

Foreman is using a self-signed certificate after installation, which
your browser does not trust.

Replace it with a certificate you bought or got via lets encrypt or
similar, or just add an exception in your browser.

··· -- Johannes Kastl Linux Consultant & Trainer Tel.: +49 (0) 151 2372 5802 Mail: kastl@b1-systems.de

B1 Systems GmbH
Osterfeldstraße 7 / 85088 Vohburg / http://www.b1-systems.de
GF: Ralph Dehner / Unternehmenssitz: Vohburg / AG: Ingolstadt,HRB 3537

Okay I'll be getting a cert from letsencrypt. Easy enough.

Will that fix my host register cert issue as well? And the katello repos
error?

Regards,

··· On Friday, March 24, 2017 at 3:41:26 PM UTC+2, Johannes Kastl wrote: > > Asjas schrieb: > > > Basically after installing foreman 1.14 on Centos 7.3 and adding the > > FQDN to my pc with the internal IP in my /etc/hosts file I can access > > the https:// website but it's giving me an SSL error. > > Foreman is using a self-signed certificate after installation, which > your browser does not trust. > > Replace it with a certificate you bought or got via lets encrypt or > similar, or just add an exception in your browser. > > -- > Johannes Kastl > Linux Consultant & Trainer > Tel.: +49 (0) 151 2372 5802 > Mail: ka...@b1-systems.de > > B1 Systems GmbH > Osterfeldstraße 7 / 85088 Vohburg / http://www.b1-systems.de > GF: Ralph Dehner / Unternehmenssitz: Vohburg / AG: Ingolstadt,HRB 3537 >

Hey,
if you use katello its not that easy, you can get the ca cert from http://foreman.tld/pub/katello-server-ca.crt and install it in your browser. If you really want a signed cert you have to do some more work – checkout the sat help: https://access.redhat.com/documentation/en-us/red_hat_satellite/6.2/html/installation_guide/installing_satellite_server#configuring_satellite_server_with_custom_server_certificate

Klaas Demter

ATIX - The Linux & Open Source Company
www.atix.de

----- Ursprüngliche Mail -----

··· Von: "Asjas" An: "Foreman users" CC: kastl@b1-systems.de Gesendet: Freitag, 24. März 2017 14:53:46 Betreff: Re: [foreman-users] Foreman Certificate Issues

Okay I’ll be getting a cert from letsencrypt. Easy enough.

Will that fix my host register cert issue as well? And the katello repos
error?

Regards,

On Friday, March 24, 2017 at 3:41:26 PM UTC+2, Johannes Kastl wrote:

Asjas schrieb:

Basically after installing foreman 1.14 on Centos 7.3 and adding the
FQDN to my pc with the internal IP in my /etc/hosts file I can access
the https:// website but it’s giving me an SSL error.

Foreman is using a self-signed certificate after installation, which
your browser does not trust.

Replace it with a certificate you bought or got via lets encrypt or
similar, or just add an exception in your browser.


Johannes Kastl
Linux Consultant & Trainer
Tel.: +49 (0) 151 2372 5802
Mail: ka...@b1-systems.de <javascript:>

B1 Systems GmbH
Osterfeldstraße 7 / 85088 Vohburg / http://www.b1-systems.de
GF: Ralph Dehner / Unternehmenssitz: Vohburg / AG: Ingolstadt,HRB 3537


You received this message because you are subscribed to the Google Groups “Foreman users” group.
To unsubscribe from this group and stop receiving emails from it, send an email to foreman-users+unsubscribe@googlegroups.com.
To post to this group, send email to foreman-users@googlegroups.com.
Visit this group at https://groups.google.com/group/foreman-users.
For more options, visit https://groups.google.com/d/optout.