Hide Forgot
It would be very beneficial to have OVN support SSL. This would be required at 2 levels: - Controller<-->northd communication - Access to north DB by external clients (including support in python API) It should be possible to set this up before starting up OVN, not as startup parameters (OVN could be running as a service).
Upstream patches posted for review: http://patchwork.ozlabs.org/patch/701569/ http://patchwork.ozlabs.org/patch/701570/ http://patchwork.ozlabs.org/patch/701571/
I'm raising the severity as this is the main issue blocking RHV ability to take OVN out of tech-preview.
Can this wait for FD production July release with OVS 2.7/RHEL 7.4, or is backport needed on OVS 2.6 (no sure if backport is feasible)? In the interim it can be made available with OVS 2.7 in FD beta channel?
(In reply to Anita Tragler from comment #4) > Can this wait for FD production July release with OVS 2.7/RHEL 7.4, or is > backport needed on OVS 2.6 (no sure if backport is feasible)? > In the interim it can be made available with OVS 2.7 in FD beta channel? We will not be able to take OVN out of tech preview without this. As long as we can test with the OVS beta channel I think we should be good until July.
This work is complete upstream, will be available when we package OVS 2.7.
Available in ovs 2.7 fd beta package, including fix for BZ 1446538. Build for testing is available here: https://brewweb.engineering.redhat.com/brew/buildinfo?buildID=560605
Verified with openvswitch-2.7.0-7.git20170530.el7fdb.x86_64 Tests including: SSL connection to north DB SSL connection to south DB SSL connection between DB and ovn-controller on the same host SSL connection between DB and ovn-controller on the different hosts