Bug 1263058

Summary: [Docs] [Ironic] Document procedures for setting up SSL
Product: Red Hat OpenStack Reporter: Lucy Bopf <lbopf>
Component: documentationAssignee: RHOS Documentation Team <rhos-docs>
Status: CLOSED WONTFIX QA Contact:
Severity: medium Docs Contact:
Priority: unspecified    
Version: 7.0 (Kilo)CC: adahms, bfournie, dtantsur, srevivo
Target Milestone: asyncKeywords: Documentation, ZStream
Target Release: 8.0 (Liberty)   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-07-11 20:29:04 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Lucy Bopf 2015-09-15 04:18:58 UTC
Create a section that outlines setting up SSL for Ironic in the Bare Metal Provisioning Guide. This has been requested by Summer Long from the security team, following a review of the draft document.

Some options for SSL are in ironic.conf, both for setting up communication with the Image server, and for any server in general.

Comment 3 Lucy Bopf 2015-09-15 04:20:31 UTC
Assigning to myself for review.

Comment 4 Andrew Dahms 2015-11-25 01:57:40 UTC
Due to current scheduling restrictions and given the scope of work required for this bug, I am returning this bug to the default assignee to be re-triaged as the schedule allows.

Comment 5 Dmitry Tantsur 2016-10-04 16:57:53 UTC
Hi! Does it even need fixing? I think we're able to setup SSL for all services nowadays..

Comment 6 Lucy Bopf 2017-02-21 00:42:41 UTC
(In reply to Dmitry Tantsur from comment #5)
> Hi! Does it even need fixing? I think we're able to setup SSL for all
> services nowadays..

Hi Dmitry,

Do you mean via director? I see that director integration was added in RHOSP 10, but in RHOSP 8 and 9, the Bare Metal Provisioning service is configured manually, so this request was to add a procedure for manually configuring SSL.

Is such a procedure still required for manual configurations, and could you help with providing the steps?

Comment 7 Dmitry Tantsur 2017-03-02 10:55:14 UTC
Ah, got it. No, sorry, I don't know how to configure SSL in this case, but it's probably the same as for other services, modulo port numbers.