Bug 1848180
| Summary: | unable to setup tls-e with public tls certs | |||
|---|---|---|---|---|
| Product: | Red Hat OpenStack | Reporter: | Ade Lee <alee> | |
| Component: | openstack-tripleo-heat-templates | Assignee: | Ade Lee <alee> | |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | Jeremy Agee <jagee> | |
| Severity: | high | Docs Contact: | ||
| Priority: | high | |||
| Version: | 16.1 (Train) | CC: | amcleod, hrybacki, mburns, ramishra, rheslop, sclewis, scohen | |
| Target Milestone: | ga | Keywords: | Triaged | |
| Target Release: | 16.1 (Train on RHEL 8.2) | |||
| Hardware: | Unspecified | |||
| OS: | Unspecified | |||
| Whiteboard: | ||||
| Fixed In Version: | Doc Type: | Known Issue | ||
| Doc Text: |
There is a known issue where a heat parameter `InternalTLSCAFile` is used during deployment when the undercloud contacts the external (public) endpoint to create initial resources and projects. If the internal and public interfaces have certificates from different Certificate Authorities (CAs), the deployment fails. Either the undercloud fails to contact the keystone public interface, or the internal interfaces receive malformed configuration.
+
This scenario affects deployments with TLS Everywhere, when the IPA server supplies the internal interfaces but the public interfaces have a certificate that the operator supplies. This also prevents 'brown field' deployments, where deployments with existing public certificates attempt to redeploy and configure TLS Everywhere.
+
There is currently no workaround for this defect.
|
Story Points: | --- | |
| Clone Of: | ||||
| : | 1852620 (view as bug list) | Environment: | ||
| Last Closed: | 2020-09-09 19:17:47 UTC | Type: | Bug | |
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Embargoed: | ||||
| Bug Depends On: | ||||
| Bug Blocks: | 1852620 | |||
|
Description
Ade Lee
2020-06-17 20:51:19 UTC
|