| Summary: | Documentation: errors wrt configuring TLS/SSL Certificates. | ||
|---|---|---|---|
| Product: | Red Hat OpenStack | Reporter: | Warren <wusui> |
| Component: | documentation | Assignee: | Dan Macpherson <dmacpher> |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | RHOS Documentation Team <rhos-docs> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 9.0 (Mitaka) | CC: | dcadzow, dgilbert, dmacpher, mburns, rhel-osp-director-maint, srevivo, wusui |
| Target Milestone: | --- | Keywords: | Reopened |
| Target Release: | --- | Flags: | wusui:
needinfo+
wusui: needinfo+ |
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2018-01-21 22:28:18 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Warren
2016-10-15 02:36:25 UTC
Merging BZ#1394452 with this BZ and taking it, since it's documentation-specific Comment from Warren: Description of problem: https://access.redhat.com/documentation/en/red-hat-openstack-platform/8/single/director-installation-and-usage/#appe-SSLTLS_Certificate_Configuration appears to not be correct in a few places. Version-Release number of selected component (if applicable): How reproducible: 100% of the time Steps to Reproduce: 1. Follow the instructions in the doc. Actual results: First off, all the issues in bugzilla 1385196 still happen in this case In addition, the openstack user could not write to /etc/pki/CA/newcerts. I manually changed its permission to 0777 (probably NOT recommended) just to work around the problem. Also, there is a definite documentation error. The command: openssl req -key ca.key.pem -new -x509 -days 7300 -extensions v3_ca -out ca.crt.pem and the command openssl ca -config openssl.cnf -extensions v3_req -days 3650 -in server.csr.pem -out server.crt.pem -cert ca.cert.pem refer to a file as ca.crt.pem and ca.cert.pem -- I think that it should be ca.cert.pem because that's what the openstack undercloud install operation expects later. *** Bug 1394453 has been marked as a duplicate of this bug. *** *** This bug has been marked as a duplicate of bug 1389766 *** Whoops, meant to be the other way around! *** Bug 1389766 has been marked as a duplicate of this bug. *** I've backported some of the components from OSP10's procedure and integrated them into OSP9's procedure. The published OSP9 doc is here: https://access.redhat.com/documentation/en-us/red_hat_openstack_platform/9/html/director_installation_and_usage/appe-ssltls_certificate_configuration Here are a list of things that have been updated: 1. Generation of the signing server files (index.txt and serial) 2. Missing --keyfile in the "openssl ca" file 3. The "openssl ca" command needs to be run as sudo 4. Corrected the cert names Warren, how does the documentation above look now? No response in over a month. Closing this BZ, but if further changes are required, please feel free to reopen. The doc changes look good. Thanks, Warren! |