Bug 1677003
| Summary: | Enable TLS-Everywhere when IdM is not on the ctlplane network | ||
|---|---|---|---|
| Product: | Red Hat OpenStack | Reporter: | Harry Rybacki <hrybacki> |
| Component: | openstack-tripleo-heat-templates | Assignee: | Ade Lee <alee> |
| Status: | CLOSED ERRATA | QA Contact: | Jeremy Agee <jagee> |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | 13.0 (Queens) | CC: | alee, cylopez, hrybacki, jagee, marjones, mburns, mircea.vutcovici, pkesavar, rcritten |
| Target Milestone: | z6 | Keywords: | Triaged, ZStream |
| Target Release: | 13.0 (Queens) | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | openstack-tripleo-heat-templates-8.2.0-7.el7ost | Doc Type: | Bug Fix |
| Doc Text: |
Previously, when using TLS Everywhere, your controller node was required to access IdM through the `ctlplane` network. As a result, if traffic was routed through a different network, then the overcloud deployment process would fail due to `getcert` errors. To address this, IdM enrolment has been moved into a composable service that runs within `host_prep_tasks`; this runs at the start of the deployment phase. Note that the script will simply exit if the instance has already been enrolled in IdM.
|
Story Points: | --- |
| Clone Of: | 1677001 | Environment: | |
| Last Closed: | 2019-04-30 17:27:36 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1677001 | ||
| Bug Blocks: | 1655185 | ||
|
Comment 1
Harry Rybacki
2019-02-28 16:25:39 UTC
Downstream build complete. Moving bug to MODIFIED. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2019:0939 *** Bug 1655185 has been marked as a duplicate of this bug. *** The needinfo request[s] on this closed bug have been removed as they have been unresolved for 1000 days |