Libvirt Service Fails to Start With Error "Cannot Read CA Certificate

Problem

The pf9-ostackhost service is down because dependent libvirtd service refuses to start with error "Cannot read CA certificate: No such file or directory".

log
Copy

Environment

  • Platform9 Managed OpenStack - v3.6.0 and Higher
  • Nova
  • Libvirt

Cause

Libvirt is configured to look for a CA certificate by default and use it to establish a TLS/SSL connection. If the correct certificate is not configured or is missing or is not applicable then libvirtd refuses to start with an error about the CA certificate.

Resolution

  1. Open the file /etc/libvirt/libvirtd.conf with a text editor and make the following changes.
Values
Copy
  1. Start the libvirtd service.
Command
Copy
  1. Start the pf9-ostackhost service.
Command
Copy
  1. If the libvirtd service still does not start, please contact Platform9 Support for further assistance.
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard