| Summary: | self-signed TLS certificates for edge terminated routes | ||
|---|---|---|---|
| Product: | OpenShift Online | Reporter: | Colin Walters <walters> |
| Component: | Routing | Assignee: | Abhishek Gupta <abhgupta> |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | zhaozhanqi <zzhao> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 3.x | CC: | aos-bugs, dakini |
| Target Milestone: | --- | Keywords: | Reopened |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2016-06-23 17:32:30 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Colin Walters
2016-05-02 18:37:19 UTC
You will need to set up your keys on your routes: https://docs.openshift.com/enterprise/3.1/dev_guide/routes.html Or set up a wildcard cert for the default routing subdomain: https://docs.openshift.com/enterprise/3.1/install_config/install/deploy_router.html#using-wildcard-certificates I'm aware I could bring my own keys, but I'd expect Online v3 to offer this by default. OpenShift v2 currently uses a wildcard *.rhcloud.com certificate from Digicert. Right? Oh! Online... sorry, completely missed that part. Apologies. Yeah, I assume they will issue a cert. I'll reopen this. Reassigning to Abhishek because this needs to be dispatched to whomever will get the Online SSL wildcard cert (if SSL will even be supported). Tested SSL certs using utility below: https://www.digicert.com/help/?host=test.1ec1.dev-preview-int.openshiftapps.com https://www.digicert.com/help/?host=test.b795.dev-preview-stg.openshiftapps.com https://www.digicert.com/help/?host=test.44fs.preview.openshiftapps.com INT/STG/Prod pass. Moving to ON_QA based on comment above by Stefanie. QE verified this bug on INT/STG. |