Conversation
get_certificate now uses get_certificate_chain: true to pull the full chain (leaf + intermediates + CA) instead of only the leaf cert. This fixes SSL trust failures in virt-v2v when the source vCenter uses a VMCA-signed certificate. Co-authored-by: Cursor <cursoragent@cursor.com>
vCenter does not include the CA certificate in its TLS handshake chain. The previous get_certificate_chain approach only retrieved the leaf cert. Now for VMware sources, the role fetches the CA certificate from the vCenter VMCA endpoint (/afd/vecs/ca), converts it from DER to PEM, and combines it with the leaf cert to build the full trust chain. This fixes SSL trust errors during virt-v2v migration connections. Co-authored-by: Cursor <cursoragent@cursor.com>
The provider secret cacert should contain only the root CA so it trusts all certs signed by that CA, including ESXi host certs that virt-v2v connects to directly during VDDK disk transfers. Co-authored-by: Cursor <cursoragent@cursor.com>
Adds a new job template for the utility_registry_credentials playbook so registry credential management can be launched from AAP with the target environment credential attached. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
tech2734
requested a deployment
to
external-ci
September 22, 2026 20:32 — with
GitHub Actions
Waiting
This branch is waiting to be deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR introduces several enhancements to the
mtv_providerrole andaap_seedrole:mtv_provider — VMCA root CA certificate retrieval
/afd/vecs/caendpoint (DER format), converts it to PEM, and stores it in the provider secret'scacertfield.virt-v2vcould not trust ESXi host connections during VDDK disk transfers.aap_seed — Registry credentials job template
OpenShift Virtualization Migration - Registry Credentials) for theutility_registry_credentialsplaybook.aap_seed_registry_credentials_template_nameandaap_seed_registry_credentials_playbook.Testing
testvm11withvalidate_certs: true— SSL trust issue resolved.aap_seed.