Bug 1391548
| Summary: | Increase default CA lifetime (advanced installation)(https://github.com/openshift/openshift-ansible/pull/2703) | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | Miheer Salunke <misalunk> |
| Component: | Installer | Assignee: | Andrew Butcher <abutcher> |
| Status: | CLOSED ERRATA | QA Contact: | Gaoyun Pei <gpei> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 3.3.0 | CC: | aos-bugs, gpei, jliggitt, jokerman, mmccomas |
| Target Milestone: | --- | ||
| Target Release: | 3.3.1 | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: |
Previously the etcd certificate authority created by the installer had an expiry date one year in the future. This has been updated to five years matching the lifespan of other certificate authorities created by the installer.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2016-11-15 19:10:58 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Miheer Salunke
2016-11-03 14:14:54 UTC
ETCD CA 5yr lifespan in https://github.com/openshift/openshift-ansible/pull/2725 Install an ocp-3.3 env with openshift-ansible-3.3.46-1.git.0.2558730.el7.noarch.rpm, check all the cert files under /etc/etcd/ directory, all the certs have 5 year lifetime now.
ca.crt
Validity
Not Before: Nov 8 07:32:42 2016 GMT
Not After : Nov 7 07:32:42 2021 GMT
Subject: CN=etcd-signer@1478590271
peer.crt
Validity
Not Before: Nov 8 07:33:00 2016 GMT
Not After : Nov 7 07:33:00 2021 GMT
Subject: CN=master-registry-etcd-1
server.crt
Validity
Not Before: Nov 8 07:32:57 2016 GMT
Not After : Nov 7 07:32:57 2021 GMT
Subject: CN=master-registry-etcd-1
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2016:2778 |