Bug 1393262
| Summary: | [networking_public_222] The cert files should be applied to all the hosts with the suffix when the route is created with wildcardpolicy enabled | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | Meng Bo <bmeng> |
| Component: | Networking | Assignee: | Ram Ranganathan <ramr> |
| Networking sub component: | router | QA Contact: | Meng Bo <bmeng> |
| Status: | CLOSED ERRATA | Docs Contact: | |
| Severity: | medium | ||
| Priority: | medium | CC: | aos-bugs, bbennett, tdawson |
| Version: | 3.4.0 | ||
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | No Doc Update | |
| Doc Text: |
undefined
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2017-01-18 12:51:10 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Meng Bo
2016-11-09 08:30:19 UTC
Should be some related discussion found here http://stackoverflow.com/questions/31262448/can-i-use-wildcard-sni-matching-with-haproxy I understand why they may want that, but it the behavior was not what we planned. Ram, do you want to weight in? Otherwise, I'd suggest opening this as an RFI. I've made the changes but will leave it to you @Ben to decide if you want to merge it or not. PR is: https://github.com/openshift/origin/pull/11862 Thx Not too scary. I've added it to the merge queue. This has been merged into ose and is in OSE v3.4.0.25 or newer. Checked on openshift v3.4.0.25, issue has been fixed. Access the route via any host which has the same suffix will use user provided certs. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2017:0066 |