Certificates permission fixed for libvirt vnc+tls
* Nova and libvirt-qemu users must have read acces to cert files.
User libvirt-qemu added to Nova group in compute state.
Change-Id: Ief10055b96c61865660b969531f63b89bfb16376
diff --git a/salt/minion/cert/libvirtd/vnc_server.yml b/salt/minion/cert/libvirtd/vnc_server.yml
index c49852e..cf60c12 100644
--- a/salt/minion/cert/libvirtd/vnc_server.yml
+++ b/salt/minion/cert/libvirtd/vnc_server.yml
@@ -22,6 +22,6 @@
key_file: ${_param:qemu_vnc_server_ssl_key_file}
cert_file: ${_param:qemu_vnc_server_ssl_cert_file}
ca_file: ${_param:qemu_vnc_ssl_ca_file}
- user: libvirt-qemu
- group: libvirt-qemu
+ user: root
+ group: nova
mode: 640