Bug 1431660
| Summary: | F5-router, Custom certificate for edge/reencrypt routes | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | Alexander Koksharov <akokshar> |
| Component: | Documentation | Assignee: | Vikram Goyal <vigoyal> |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | Vikram Goyal <vigoyal> |
| Severity: | high | Docs Contact: | Vikram Goyal <vigoyal> |
| Priority: | unspecified | ||
| Version: | 3.4.0 | CC: | ahardin, aos-bugs, eparis, erich, hongli, jokerman, mmccomas |
| Target Milestone: | --- | ||
| Target Release: | 3.5.z | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Known Issue | |
| Doc Text: |
Cause: we do not create vservers automatically, so handling of default certs has to be manually.
Consequence: Default certs are not copied by the router pod.
Workaround (if any):
Result:
User guide has been updated on how to set the default certificate.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2017-08-16 20:00:49 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Alexander Koksharov
2017-03-13 14:33:03 UTC
The edge routes will be terminated if the vserver has been set with a default client cert profile properly. Otherwise when the F5 pod controller does a 'POST' of custom certificates of a route, we receive an error about no certificate being the default one. To set any of the certs as default, one should likely do this at vserver setup time. See this: https://support.f5.com/csp/article/K13452 In the section: Configuring the fallback (default) client SSL profile Step #11 suggests to click the default setting to true This should all go under the rather incomplete documentation. Will post the doc PR as part of this bug fix. Documentation fixed by: https://github.com/openshift/openshift-docs/pull/4090 I followed this docs and created both http and https vserver in my F5 test evn, the edge route works well with TLS SNI enabled. |