Bug 1855678

Summary: Configure Ceph Messenger for encryption OTW
Product: Red Hat OpenStack Reporter: Giulio Fidente <gfidente>
Component: openstack-tripleo-heat-templatesAssignee: Giulio Fidente <gfidente>
Status: CLOSED ERRATA QA Contact: Yogev Rabl <yrabl>
Severity: medium Docs Contact:
Priority: high    
Version: 16.1 (Train)CC: alfrgarc, fpantano, gcharot, lmarsh, mburns, nwolf, pgrist, spower, tvignaud, yrabl
Target Milestone: z2Keywords: FutureFeature, Triaged
Target Release: 16.2 (Train on RHEL 8.4)   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: openstack-tripleo-heat-templates-11.6.1-2.20210702224947.2a63ac5.el8ost Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-03-23 22:28:29 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1978286    

Description Giulio Fidente 2020-07-10 09:08:44 UTC
We should provide users with an option to enable:

"""
ms_cluster_mode=secure
ms_service_mode=secure
ms_client_mode=secure
"""

in ceph.conf [mons] (or [global]) section so that Ceph is configured to do encryption for its messenger protocol

Comment 11 spower 2020-09-08 13:22:33 UTC
Approved for 16.1.2 on condition is that it goes tech preview if testing doesn't finish

Comment 21 Yogev Rabl 2022-01-26 19:55:18 UTC
This bug has already been resolved and verified

Comment 30 errata-xmlrpc 2022-03-23 22:28:29 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: Red Hat OpenStack Platform 16.2 (openstack-tripleo-heat-templates) security update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2022:0995