Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1571990 - [Deployment] [TLS] ODL OVS needs to add certificates to every ODL node
[Deployment] [TLS] ODL OVS needs to add certificates to every ODL node
Status: CLOSED ERRATA
Product: Red Hat OpenStack
Classification: Red Hat
Component: puppet-neutron (Show other bugs)
13.0 (Queens)
Unspecified Unspecified
urgent Severity urgent
: beta
: 13.0 (Queens)
Assigned To: Tim Rozet
Itzik Brown
odl_deployment, odl_tls
: Triaged
Depends On:
Blocks: 1488826
  Show dependency treegraph
 
Reported: 2018-04-25 17:42 EDT by Tim Rozet
Modified: 2018-10-18 03:21 EDT (History)
6 users (show)

See Also:
Fixed In Version: puppet-neutron-12.4.1-0.20180412211913
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
N/A
Last Closed: 2018-06-27 09:53:50 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Launchpad 1766989 None None None 2018-04-25 17:54 EDT
OpenStack gerrit 565281 None stable/queens: MERGED puppet-neutron: Fixes ODL OVS to add certs to every node (Ifd8401e2facdad07ccda4ec6f885a82bc0a16421) 2018-05-01 12:41 EDT
Red Hat Product Errata RHEA-2018:2086 None None None 2018-06-27 09:55 EDT

  None (edit)
Description Tim Rozet 2018-04-25 17:42:24 EDT
Description of problem:
In the current behavior, the OVS configuration for ODL adds a certificate to ODL via the VIP.  This works fine in no-ha deployments, but in HA it only results in 1 ODL instance adding the certificate, so only 1 ODL accepts an OVSDB connection. This is because of issues with using MD-SAL trust store type (see https://bugzilla.redhat.com/show_bug.cgi?id=1571985).  Since MD-SAL trust store doesn't work, we have to use a file based trust store.  In that case the file is not highly available, so we need to add the certificate to every ODL node.

How reproducible:
Always in SSL/TLS HA ODL deployment
Comment 6 Itzik Brown 2018-05-03 09:52:54 EDT
Checked with:
puppet-neutron-12.4.1-0.20180412211913.el7ost.noarch
Comment 10 errata-xmlrpc 2018-06-27 09:53:50 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2018:2086

Note You need to log in before you can comment on or make changes to this bug.