Bug 1855403

Summary: stop supporting deprecated TLS/E with novajoin
Product: Red Hat OpenStack Reporter: Ade Lee <alee>
Component: openstack-tripleo-heat-templatesAssignee: Ade Lee <alee>
Status: CLOSED ERRATA QA Contact: Jeremy Agee <jagee>
Severity: high Docs Contact:
Priority: high    
Version: 17.0 (Wallaby)CC: bdobreli, hrybacki, jschluet, jwakely, lbragsta, mburns, scohen, tkajinam
Target Milestone: AlphaKeywords: Triaged
Target Release: 17.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: openstack-tripleo-heat-templates-14.3.1-0.20220617150351.66bbda8.el9ost Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-09-21 12:10:55 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1848153    

Description Ade Lee 2020-07-09 19:02:08 UTC
Description of problem:

As of 16.1, deploying TLS-Everywhere with Novajoin has been deprecated in favor of using a new ansible based approach (tripleo-ipa).  

The new approach is expected to be more robust and maintainable, and is required for nova-less deployments (like those using pre-provisioned nodes) and for services such as cinder A/A (with full TLS-E support).  It is also required for brown field deployments in 16.1+.

The plan is to remove TLS-E via novajoin upstream in the Victoria cycle.  This BZ is to track that work downstream.

16.1 supports TLS-E using both methods, but the novajoin way is the default.  The goal here is to remove the novajoin way and provide all the required migration scripts to do this as seamlessly as possible.

Version-Release number of selected component (if applicable):


How reproducible:


Steps to Reproduce:
1.
2.
3.

Actual results:


Expected results:


Additional info:

Comment 12 Rachel Goodman 2022-07-18 09:53:54 UTC Comment hidden (spam)
Comment 18 errata-xmlrpc 2022-09-21 12:10:55 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Release of components for Red Hat OpenStack Platform 17.0 (Wallaby)), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2022:6543

Comment 31 Patricia 2022-12-29 04:22:31 UTC Comment hidden (spam)
Comment 33 Nanisa Han 2023-02-16 06:58:45 UTC Comment hidden (spam)
Comment 34 sarafoster 2023-03-01 10:45:01 UTC Comment hidden (spam)
Comment 35 Faridariska 2023-06-12 13:57:05 UTC Comment hidden (spam)
Comment 36 Robin Sinks 2023-06-30 21:18:36 UTC Comment hidden (spam)
Comment 37 pawan tanwar 2023-07-13 09:16:24 UTC Comment hidden (spam)
Comment 38 pawan tanwar 2023-07-13 09:16:55 UTC Comment hidden (spam)
Comment 39 Carter Kim 2023-12-21 09:54:05 UTC Comment hidden (spam)
Comment 40 hema2011 2023-12-30 04:55:37 UTC Comment hidden (spam)
Comment 41 Shauna Brown 2024-04-18 08:32:13 UTC Comment hidden (spam)
Comment 42 Welsh 2024-09-05 08:19:19 UTC Comment hidden (spam)
Comment 43 Michael Gardner 2024-09-17 10:01:01 UTC Comment hidden (spam)
Comment 44 gary589byers 2024-09-23 09:48:10 UTC Comment hidden (spam)