Bug 1479930 - [3.2] Hawkular Metrics cannot handle connecting to the Kubernetes Master when the ca.crt contains multiple certificates. [NEEDINFO]
[3.2] Hawkular Metrics cannot handle connecting to the Kubernetes Master when...
Product: OpenShift Container Platform
Classification: Red Hat
Component: Metrics (Show other bugs)
Unspecified Unspecified
urgent Severity urgent
: ---
: 3.2.1
Assigned To: Matt Wringe
Junqi Zhao
Depends On: 1447463 1461635
Blocks: 1468308 1468309
  Show dependency treegraph
Reported: 2017-08-09 14:52 EDT by Matt Wringe
Modified: 2018-06-01 13:59 EDT (History)
14 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Cause: The Java keytool command can only handle importing single individual certificates. The OpenShift ca bundle certificates can contain multiple ca certificates. Consequence: When importing the ca certificate from OpenShift, the Java keytool command would only import the first certificate and ignore the rest. Fix: Instead of directly importing the CA certicate from OpenShift directly, we need to split up the certificate into individual certificates and load them individually. Result: Hawkular Metrics can now trust certificates signed by any of the CA certificates in the OpenShift CA bundle.
Story Points: ---
Clone Of: 1461635
Last Closed: 2018-06-01 13:59:10 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
erjones: needinfo? (smunilla)

Attachments (Terms of Use)

  None (edit)
Comment 4 Junqi Zhao 2017-08-17 00:26:59 EDT
Issue was fixed.

Verification steps:
1. Add the example certificate in https://bugzilla.redhat.com/show_bug.cgi?id=1447463#c53 before and after /etc/origin/master/ca-bundle.crt.
2. Restart server and deploy metrics 3.2.1 by using images from brew registry.
   cat /var/run/secrets/kubernetes.io/serviceaccount/ca.crt

/var/run/secrets/kubernetes.io/serviceaccount/ca.crt is the same with /etc/origin/master/ca-bundle.crt.

4. Login web console, metrics can  be viewed.
Comment 5 Junqi Zhao 2017-08-17 00:28:19 EDT
# openshift version
openshift v3.2.1.34
kubernetes v1.2.0-36-g4a3f9c5
etcd 2.2.5


Note You need to log in before you can comment on or make changes to this bug.