Bug 1292488 - [RFE] Allow root CA configuration for SSL enabled Openstack connectivity
[RFE] Allow root CA configuration for SSL enabled Openstack connectivity
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: Providers (Show other bugs)
Unspecified Unspecified
unspecified Severity high
: GA
: 5.5.2
Assigned To: Ladislav Smola
Aziza Karol
: FutureFeature, ZStream
Depends On: 1292409
  Show dependency treegraph
Reported: 2015-12-17 10:10 EST by John Prause
Modified: 2016-02-10 10:29 EST (History)
12 users (show)

See Also:
Fixed In Version:
Doc Type: Enhancement
Doc Text:
With this update, it is now possible to specify the path to a CA certificate for OpenStack providers to allow SSL connectivity.
Story Points: ---
Clone Of: 1292409
Last Closed: 2016-02-10 10:29:26 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Comment 3 CFME Bot 2016-01-12 14:30:01 EST
New commit detected on cfme/5.5.z:

commit 063a102f11f053e4931cdf40be3ce022f2914f36
Merge: ccc121c 95847a9
Author:     Greg Blomquist <gblomqui@redhat.com>
AuthorDate: Tue Jan 12 13:47:39 2016 -0500
Commit:     Greg Blomquist <gblomqui@redhat.com>
CommitDate: Tue Jan 12 13:47:39 2016 -0500

    Merge branch 'bz1292488' into '5.5.z'
    OpenStack allow to specify path to CA certificate
    OpenStack allow to specify path to CA certificate, which will be
    passed to Excon.
    5.5.z BZ:
    Conflict in tests of cherry-pick of:
    Conflict is due to should -> expect change for rspec 3
    See merge request !709

 .../manageiq/providers/openstack/manager_mixin.rb  |   9 +-
 config/vmdb.tmpl.yml                               |   3 +
 gems/pending/openstack/openstack_handle/handle.rb  |  24 ++++-
 .../spec/openstack/openstack_handle/handle_spec.rb | 100 ++++++++++++++++++++-
 4 files changed, 127 insertions(+), 9 deletions(-)
Comment 6 Ronnie Rasouli 2016-02-01 03:50:31 EST
tested on
with SSL configured on 7.3 

Copied both CA for undercloud and overcloud to CFME

modified in configure-> configuration-> advanced 
ssl_ca_file: "/etc/pki/tls/certs/ca-bundle.crt"

Both undercloud and overcloud with SSL are working
Comment 7 errata-xmlrpc 2016-02-10 10:29:26 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.