Bug 1949941

Summary: create an information alert about the old-format tokens being unusable starting 4.8
Product: OpenShift Container Platform Reporter: Standa Laznicka <slaznick>
Component: apiserver-authAssignee: Standa Laznicka <slaznick>
Status: CLOSED ERRATA QA Contact: pmali
Severity: high Docs Contact:
Priority: high    
Version: 4.7CC: aos-bugs, mfojtik, sttts
Target Milestone: ---   
Target Release: 4.7.z   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Deprecated Functionality
Doc Text:
In the upcoming OpenShift version (4.8), the old-format OAuth tokens (not prepended by sha256~ prefix) will no longer be usable and noone will be able to create them. If an OpenShift 4.7 cluster contains such old-format OAuth tokens, we now raise an informational alert to notify the administrators of the cluster about this behavior change.
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-05-19 15:16:13 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1944631    
Bug Blocks:    
Attachments:
Description Flags
prometheus none

Description Standa Laznicka 2021-04-15 12:35:17 UTC
Description of problem:
We've removed the ability to create or authenticate with tokens that do not have hashed names.

In 4.7, we need to add an informational alert that this is going to happen.

Version-Release number of selected component (if applicable):
4.7

How reproducible:
always

Steps to Reproduce:
1. manually create a non-hashed access/authorize token in the API and attempt to use it

Actual results:
nothing interesting happens

Expected results:
An information-level alert should be created

Comment 1 Standa Laznicka 2021-04-16 10:54:05 UTC
*** Bug 1877713 has been marked as a duplicate of this bug. ***

Comment 5 pmali 2021-05-04 03:20:20 UTC
Created attachment 1779179 [details]
prometheus

Comment 6 Siddharth Sharma 2021-05-10 17:58:27 UTC
This bug will be shipped as part of next z-stream release 4.7.11 on May 19th, as 4.7.10 was dropped due to a blocker https://bugzilla.redhat.com/show_bug.cgi?id=1958518.

Comment 10 errata-xmlrpc 2021-05-19 15:16:13 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (OpenShift Container Platform 4.7.11 bug fix update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2021:1550