Back to bug 1382020

Who When What Removed Added
Fabiano Franz 2016-10-05 14:35:12 UTC Status NEW ON_QA
Target Release --- 3.3.1
CC ejacobs, jliggitt
Doc Text Cause:
With a malformed master certificate (e.g. expired, mismatched hostname), the latest version of 'oc login' will not ignore this problem even when --insecure-skip-tls-verify is set.

Consequence:
Users can't login with 'oc' when the server master certificate is invalid.

Fix:
Handle TLS failures more precisely and allow --insecure-skip-tls-verify to bypass the following error causes:
* certificate hostname mismatch
* certificate expired
* CA not authorized
* too many intermediates
* usage incompatible with the certificate purpose

Result:
Users can bypass the certificate error and login with --insecure-skip-tls-verify.
Doc Type If docs needed, set a value Bug Fix
XiaochuanWang 2016-10-08 08:41:59 UTC Status ON_QA VERIFIED
CC xiaocwan
errata-xmlrpc 2016-10-25 10:51:40 UTC Status VERIFIED RELEASE_PENDING
errata-xmlrpc 2016-10-27 15:42:59 UTC Status RELEASE_PENDING CLOSED
Resolution --- ERRATA
Last Closed 2016-10-27 11:42:59 UTC

Back to bug 1382020