Bug 1456743 - Unable to configure TLS parameters
Summary: Unable to configure TLS parameters
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: python-PyMySQL
Version: 12.0 (Pike)
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: Upstream M2
: 12.0 (Pike)
Assignee: RHOS Maint
QA Contact: Udi Shkalim
URL:
Whiteboard:
Depends On:
Blocks: 1486759
TreeView+ depends on / blocked
 
Reported: 2017-05-30 09:53 UTC by Juan Antonio Osorio
Modified: 2018-02-05 19:07 UTC (History)
11 users (show)

Fixed In Version: python-PyMySQL-0.7.11-1.el7ost
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2017-12-13 21:29:42 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHEA-2017:3462 0 normal SHIPPED_LIVE Red Hat OpenStack Platform 12.0 Enhancement Advisory 2018-02-16 01:43:25 UTC

Description Juan Antonio Osorio 2017-05-30 09:53:01 UTC
Description of problem:
With the current version of PyMySQL in RDO, I am unable to configure TLS parameters in the configuration file. This functionality was introduced in a further release (specifically version 0.7.11 https://github.com/PyMySQL/PyMySQL/commit/f6d28536493596e4ff7b87cf4d5201d657dae44d ).

This is needed since currently there is no way to configure such things (such as the CA and enabling TLS for the client connections, via oslo.db. So adding these parameters via the configuration file solves the issue.

Comment 4 Damien Ciabrini 2017-10-17 09:55:17 UTC
Testing plan:

This bug is about bumping the version of PyMySQL to ensure that python client can read SSL config to connect to MySQL/galera over TLS, which wasn't the case in prior version.

So the basic test strategy is "Deploy an overcloud with 'TLS everywhere' enabled". If the deploy is succesfull, you validated this bug.

Comment 6 Udi Shkalim 2017-11-16 17:34:09 UTC
Package python-PyMySQL-0.7.11-1.el7ost is present in osp12 builds on controllers.

Comment 9 errata-xmlrpc 2017-12-13 21:29:42 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2017:3462


Note You need to log in before you can comment on or make changes to this bug.