Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1571988 - [Deployment][TLS] MD-SAL based trust keystore needs to be disabled in HA
[Deployment][TLS] MD-SAL based trust keystore needs to be disabled in HA
Status: CLOSED ERRATA
Product: Red Hat OpenStack
Classification: Red Hat
Component: puppet-opendaylight (Show other bugs)
13.0 (Queens)
Unspecified Unspecified
urgent Severity urgent
: beta
: 13.0 (Queens)
Assigned To: Tim Rozet
Itzik Brown
odl_deployment,odl_tls
: Triaged
Depends On:
Blocks: 1488826
  Show dependency treegraph
 
Reported: 2018-04-25 17:36 EDT by Tim Rozet
Modified: 2018-10-18 03:19 EDT (History)
7 users (show)

See Also:
Fixed In Version: puppet-opendaylight-8.1.2-1.38977efgit.el7ost
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
N/A
Last Closed: 2018-06-27 09:53:50 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
OpenDaylight Bug INTPAK-164 None None None 2018-04-25 17:45 EDT
RDO 13605 None queens-rdo: NEW puppet/puppet-opendaylight-distgit: puppet-opendaylight-8.1.2-1.38977efgit (I08f26d91ff0e9ee56cc177a3abdaf96ea505994c) 2018-05-01 10:17 EDT
OpenDaylight gerrit 71362 None None None 2018-04-26 11:33 EDT
Red Hat Product Errata RHEA-2018:2086 None None None 2018-06-27 09:55 EDT

  None (edit)
Description Tim Rozet 2018-04-25 17:36:42 EDT
Description of problem:
Due to the lack of support for MD-SAL based truststore in ODL, we need to disable it and only use a file based truststore.  Currently we use a file based truststore for no-ha deployments, and we use MD-SAL for HA.  However since MD-SAL truststore is non-functional (see https://bugzilla.redhat.com/show_bug.cgi?id=1571985) we need to disable it even in the HA scenario.

Version-Release number of selected component (if applicable):
OSP13

How reproducible:
Reproducible in SSL/TLS HA deployments

Steps to Reproduce:
1. Deploy SSL/TLS in HA with ODL
2. Deployment will succeed, but OVSDB and OF in OVS connections will be down
Comment 1 Daniel Farrell 2018-04-25 19:16:32 EDT
Fix merged upstream: https://git.opendaylight.org/gerrit/#/c/71362/
Comment 2 Jon Schlueter 2018-05-01 10:30:04 EDT
proposed 8.1.2 version cbs build to RDO and built same for this bug for OSP 13
Comment 7 Itzik Brown 2018-05-03 04:22:33 EDT
Checked with:
puppet-opendaylight-8.1.2-1.38977efgit.el7ost.noarch
Comment 11 errata-xmlrpc 2018-06-27 09:53:50 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2018:2086

Note You need to log in before you can comment on or make changes to this bug.