Bug 1110441

Summary: add ntp update
Product: Red Hat OpenStack Reporter: Dan Radez <dradez>
Component: rhel-osp-installerAssignee: Dan Radez <dradez>
Status: CLOSED ERRATA QA Contact: Omri Hochman <ohochman>
Severity: high Docs Contact:
Priority: high    
Version: 5.0 (RHEL 6)CC: dradez, mburns, rhos-maint, sgordon, slong
Target Milestone: ga   
Target Release: 5.0 (RHEL 6)   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: foreman-installer-staypuft-0.0.21.el6ost Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-08-04 18:34:49 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Dan Radez 2014-06-17 16:09:03 UTC
Description of problem:
and ntp update should be performed post network config and pre-SSL-CA generation

Version-Release number of selected component (if applicable):
0.0.19

How reproducible:
Feature req

Steps to Reproduce:
1.
2.
3.

Actual results:
puppet will fail to run on nodes being provisioned if dates are not synced

Expected results:
puppet should run

Additional info:

Comment 3 Omri Hochman 2014-06-18 13:11:38 UTC
Non-running ntpd might cause a certificate problems on the associate hosts during the deployment  - and deployment can get stuck during process over "certificate verify failed:" : 


Messages: 
----------
Jun 17 20:47:56 001a4a169876 puppet-agent[3321]: Reopening log files
Jun 17 20:47:56 001a4a169876 systemd: Started Puppet agent.
Jun 17 20:47:56 001a4a169876 puppet-agent[3321]: Starting Puppet client version 3.4.3
Jun 17 20:47:56 001a4a169876 NetworkManager[639]: <info> startup complete
Jun 17 20:47:57 001a4a169876 puppet-agent[3348]: Unable to fetch my node definition, but the agent run will continue:
Jun 17 20:47:57 001a4a169876 puppet-agent[3348]: SSL_connect returned=1 errno=0 state=SSLv3 read server certificate B: certificate verify failed: [CRL is not yet valid for /CN=livecd.example.com]
Jun 17 20:47:57 001a4a169876 puppet-agent[3348]: (/File[/var/lib/puppet/lib]) Failed to generate additional resources using 'eval_generate': SSL_connect returned=1 errno=0 state=SSLv3 read server certificate B: certificate verify failed: [CRL is not yet valid for /CN=livecd.example.com]
Jun 17 20:47:57 001a4a169876 puppet-agent[3348]: (/File[/var/lib/puppet/lib]) Could not evaluate: SSL_connect returned=1 errno=0 state=SSLv3 read server certificate B: certificate verify failed: [CRL is not yet valid for /CN=livecd.example.com] Could not retrieve file metadata for puppet://livecd.example.com/plugins: SSL_connect returned=1 errno=0 state=SSLv3 read server certificate B: certificate verify failed: [CRL is not yet valid for /CN=livecd.example.com]
Jun 17 20:47:57 001a4a169876 dracut: dracut module 'plymouth' will not be installed, because it's in the list to be omitted!
Jun 17 20:47:58 001a4a169876 puppet-agent[3348]: Could not retrieve catalog from remote server: SSL_connect returned=1 errno=0 state=SSLv3 read server certificate B: certificate verify failed: [CRL is not yet valid for /CN=livecd.example.com]
Jun 17 20:47:58 001a4a169876 puppet-agent[3348]: Using cached catalog
Jun 17 20:47:58 001a4a169876 puppet-agent[3348]: Could not retrieve catalog; skipping run
Jun 17 20:47:58 001a4a169876 puppet-agent[3348]: Could not send report: SSL_connect returned=1 errno=0 state=SSLv3 read server certificate B: certificate verify failed: [CRL is not yet valid for /CN=livecd.example.com]

Comment 4 Dan Radez 2014-06-20 19:46:03 UTC
https://github.com/theforeman/foreman-installer-staypuft/pull/23

ready for upstream merge.

Comment 6 Omri Hochman 2014-07-01 20:23:33 UTC
Verified with rhel-osp-installer-0.0.25-5.el6ost.noarch

NTP is now being configured as part of the installer run:  (NTP sync host: 'clock.redhat.com' )

In case NTP is not configured or miss-configured - installation will fail.

Comment 9 errata-xmlrpc 2014-08-04 18:34:49 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHEA-2014-1003.html