Bug 1479428 - [RFE] Capsule need to trust all 'default CAs' in a Satellite cluster
Summary: [RFE] Capsule need to trust all 'default CAs' in a Satellite cluster
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat Satellite
Classification: Red Hat
Component: Certificates
Version: 6.2.9
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: Unspecified
Assignee: Sean O'Keeffe
QA Contact: Stephen Wadeley
URL:
Whiteboard:
Depends On:
Blocks: 1196002
TreeView+ depends on / blocked
 
Reported: 2017-08-08 14:32 UTC by Sean O'Keeffe
Modified: 2024-02-28 20:32 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Enhancement
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-11-22 17:58:10 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Foreman Issue Tracker 20021 0 Normal New Optionally create a katello-default-ca with public CA certs from multiple sources 2019-12-20 10:44:01 UTC

Description Sean O'Keeffe 2017-08-08 14:32:21 UTC
Description of problem:
A Satellite cluster requires capsules trust the 'default ca' on every Satellite server. 


Version-Release number of selected component (if applicable):
6.2.9


How reproducible:
100%

Steps to Reproduce:
1. Build 2 Satellites, /var/lib/pgsql, /var/lib/mongodb, /var/lib/pulp on shared storage
- Start services on node 1, Stop services on node 2
- installer:
  - ensure various oauth_options are the same on both nodes
  - ensure db_passoword options are the same on both nodes
  - provide the same custom certs with multiple dns alt names
  - ensure /etc/foreman/encryption_key.rb is the same on both nodes
4. confirm fail over works
  a. stop services on node 1 
  b. fail over storage
  c. start services on node 2
3. on the active node generate certs with custom certificates and register a capsule (all should be working)
4. fail over again and any communication with the proxy will fail from this node with SSL errors.

Actual results:
SSL errors

Expected results:
Proxy comms to work


Additional info:
I can supply better details to reproduce this if required..

Comment 2 Bryan Kearney 2019-11-05 20:41:34 UTC
Upstream bug assigned to sokeeffe

Comment 3 Bryan Kearney 2019-11-22 17:58:10 UTC
Thank you for your interest in Satellite 6. We have evaluated this request, and while we recognize that it is a valid request, we do not expect this to be implemented in the product in the foreseeable future. This is due to other priorities for the product, and not a reflection on the request itself. We are therefore closing this out as WONTFIX. If you have any concerns about this, please do not reopen. Instead, feel free to contact Red Hat Technical Support. Thank you.


Note You need to log in before you can comment on or make changes to this bug.