Bug 1456743

Summary: Unable to configure TLS parameters
Product: Red Hat OpenStack Reporter: Juan Antonio Osorio <josorior>
Component: python-PyMySQLAssignee: RHOS Maint <rhos-maint>
Status: CLOSED ERRATA QA Contact: Udi Shkalim <ushkalim>
Severity: medium Docs Contact:
Priority: medium    
Version: 12.0 (Pike)CC: apevec, dciabrin, fdinitto, jschluet, kbasil, lhh, mburns, nlevinki, scorcora, tvignaud, ushkalim
Target Milestone: Upstream M2Keywords: Triaged
Target Release: 12.0 (Pike)   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: python-PyMySQL-0.7.11-1.el7ost Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-12-13 21:29:42 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1486759    

Description Juan Antonio Osorio 2017-05-30 09:53:01 UTC
Description of problem:
With the current version of PyMySQL in RDO, I am unable to configure TLS parameters in the configuration file. This functionality was introduced in a further release (specifically version 0.7.11 https://github.com/PyMySQL/PyMySQL/commit/f6d28536493596e4ff7b87cf4d5201d657dae44d ).

This is needed since currently there is no way to configure such things (such as the CA and enabling TLS for the client connections, via oslo.db. So adding these parameters via the configuration file solves the issue.

Comment 4 Damien Ciabrini 2017-10-17 09:55:17 UTC
Testing plan:

This bug is about bumping the version of PyMySQL to ensure that python client can read SSL config to connect to MySQL/galera over TLS, which wasn't the case in prior version.

So the basic test strategy is "Deploy an overcloud with 'TLS everywhere' enabled". If the deploy is succesfull, you validated this bug.

Comment 6 Udi Shkalim 2017-11-16 17:34:09 UTC
Package python-PyMySQL-0.7.11-1.el7ost is present in osp12 builds on controllers.

Comment 9 errata-xmlrpc 2017-12-13 21:29:42 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2017:3462