Bug 1571988 - [Deployment][TLS] MD-SAL based trust keystore needs to be disabled in HA
Summary: [Deployment][TLS] MD-SAL based trust keystore needs to be disabled in HA
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: puppet-opendaylight
Version: 13.0 (Queens)
Hardware: Unspecified
OS: Unspecified
Target Milestone: beta
: 13.0 (Queens)
Assignee: Tim Rozet
QA Contact: Itzik Brown
Whiteboard: odl_deployment,odl_tls
Depends On:
Blocks: 1488826
TreeView+ depends on / blocked
Reported: 2018-04-25 21:36 UTC by Tim Rozet
Modified: 2018-10-18 07:19 UTC (History)
7 users (show)

Fixed In Version: puppet-opendaylight-8.1.2-1.38977efgit.el7ost
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed: 2018-06-27 13:53:50 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
OpenDaylight Bug INTPAK-164 0 None None None 2018-04-25 21:45:24 UTC
OpenDaylight gerrit 71362 0 None None None 2018-04-26 15:33:10 UTC
RDO 13605 0 None queens-rdo: NEW puppet/puppet-opendaylight-distgit: puppet-opendaylight-8.1.2-1.38977efgit (I08f26d91ff0e9ee56cc177a3abdaf96ea505994c) 2018-05-01 14:17:06 UTC
Red Hat Product Errata RHEA-2018:2086 0 None None None 2018-06-27 13:55:07 UTC

Description Tim Rozet 2018-04-25 21:36:42 UTC
Description of problem:
Due to the lack of support for MD-SAL based truststore in ODL, we need to disable it and only use a file based truststore.  Currently we use a file based truststore for no-ha deployments, and we use MD-SAL for HA.  However since MD-SAL truststore is non-functional (see https://bugzilla.redhat.com/show_bug.cgi?id=1571985) we need to disable it even in the HA scenario.

Version-Release number of selected component (if applicable):

How reproducible:
Reproducible in SSL/TLS HA deployments

Steps to Reproduce:
1. Deploy SSL/TLS in HA with ODL
2. Deployment will succeed, but OVSDB and OF in OVS connections will be down

Comment 1 Daniel Farrell 2018-04-25 23:16:32 UTC
Fix merged upstream: https://git.opendaylight.org/gerrit/#/c/71362/

Comment 2 Jon Schlueter 2018-05-01 14:30:04 UTC
proposed 8.1.2 version cbs build to RDO and built same for this bug for OSP 13

Comment 7 Itzik Brown 2018-05-03 08:22:33 UTC
Checked with:

Comment 11 errata-xmlrpc 2018-06-27 13:53:50 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.