VM migration between OpenShift clusters fails with "x509: certificate signed by unknown authority" after ingress certificate update

Solution Verified - Updated -

Issue

When attempting to migrate a Virtual Machine from one OpenShift cluster to another using MTV, the migration fails during the export/import phase.

The Migration or DataVolume objects report a TLS certificate verification failure when attempting to connect to the source cluster's virt-exportproxy endpoint to fetch the VM manifest or disk image.

VM migration between OpenShift clusters fails with "x509: certificate signed by unknown authority" after ingress certificate update
message: 'Unable to connect to http data source: HTTP request errored: Get "https://virt-exportproxy-openshift-cnv.apps.<cluster-domain>/api/export.kubevirt.io/v1beta1/namespaces/<namespace>/virtualmachineexports/<export-name>/volumes/<volume-name>/disk.img.gz": tls: failed to verify certificate: x509: certificate signed by unknown authority'

Environment

  • Red Hat OpenShift Container Platform
    • 4.18
    • 4.19
    • 4.20
    • 4.21
    • 4.22
  • OpenShift Virtualization
    • 4.18
    • 4.19
    • 4.20
    • 4.21
    • 4.22
  • Migration Toolkit for Virtualization (MTV)
    • 2.12

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content