Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1456743 - Unable to configure TLS parameters
Unable to configure TLS parameters
Status: CLOSED ERRATA
Product: Red Hat OpenStack
Classification: Red Hat
Component: python-PyMySQL (Show other bugs)
12.0 (Pike)
Unspecified Unspecified
medium Severity medium
: Upstream M2
: 12.0 (Pike)
Assigned To: RHOS Maint
Udi Shkalim
: Triaged
Depends On:
Blocks: 1486759
  Show dependency treegraph
 
Reported: 2017-05-30 05:53 EDT by Juan Antonio Osorio
Modified: 2018-02-05 14:07 EST (History)
11 users (show)

See Also:
Fixed In Version: python-PyMySQL-0.7.11-1.el7ost
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2017-12-13 16:29:42 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHEA-2017:3462 normal SHIPPED_LIVE Red Hat OpenStack Platform 12.0 Enhancement Advisory 2018-02-15 20:43:25 EST

  None (edit)
Description Juan Antonio Osorio 2017-05-30 05:53:01 EDT
Description of problem:
With the current version of PyMySQL in RDO, I am unable to configure TLS parameters in the configuration file. This functionality was introduced in a further release (specifically version 0.7.11 https://github.com/PyMySQL/PyMySQL/commit/f6d28536493596e4ff7b87cf4d5201d657dae44d ).

This is needed since currently there is no way to configure such things (such as the CA and enabling TLS for the client connections, via oslo.db. So adding these parameters via the configuration file solves the issue.
Comment 4 Damien Ciabrini 2017-10-17 05:55:17 EDT
Testing plan:

This bug is about bumping the version of PyMySQL to ensure that python client can read SSL config to connect to MySQL/galera over TLS, which wasn't the case in prior version.

So the basic test strategy is "Deploy an overcloud with 'TLS everywhere' enabled". If the deploy is succesfull, you validated this bug.
Comment 6 Udi Shkalim 2017-11-16 12:34:09 EST
Package python-PyMySQL-0.7.11-1.el7ost is present in osp12 builds on controllers.
Comment 9 errata-xmlrpc 2017-12-13 16:29:42 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2017:3462

Note You need to log in before you can comment on or make changes to this bug.