Bugzilla (bugzilla.redhat.com) will be under maintenance for infrastructure upgrades and will not be available on July 31st between 12:30 AM - 05:30 AM UTC. We appreciate your understanding and patience. You can follow status.redhat.com for details.
Bug 1879035 - expired token should be renewed on downloading host boot disks
Summary: expired token should be renewed on downloading host boot disks
Alias: None
Product: Red Hat Satellite
Classification: Red Hat
Component: Bootdisk Plugin
Version: 6.8.0
Hardware: Unspecified
OS: Unspecified
Target Milestone: 6.9.0
Assignee: Lukas Zapletal
QA Contact: Roman Plevka
Depends On:
TreeView+ depends on / blocked
Reported: 2020-09-15 09:18 UTC by Roman Plevka
Modified: 2021-01-19 10:34 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed: 2021-01-19 10:34:05 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Foreman Issue Tracker 31674 0 Normal New Expired token should be renewed on downloading host boot disks 2021-01-19 10:34:05 UTC

Description Roman Plevka 2020-09-15 09:18:55 UTC
Description of problem:
When a provisioning token for a host is expired, downloading a bootdisk for the host effectively generates an outdated image (with the invalid token) and thus making the images useless.

Version-Release number of selected component (if applicable):

Steps to Reproduce:
1. create a host record
2. [optionally shorten the token validity time]
3. wait for the token to expire
4. generate a full host image
5. try to boot it

Actual results:
kickstart file is unable to retrieve as the old, invalid token is used

Expected results:
Downloading of the bootdisk should involce re-generating a provisioning token
Ideally, there should be a warning dialog with an option to confirm the refreshing of the token.
This would save the effort of generating and downloading of an useless image.

Additional info:

Comment 2 Lukas Zapletal 2020-09-17 07:01:16 UTC
There is one problem tho - to generate token, host must be in build mode. And download action shoud NOT turn on build mode, because if user accidentally does this and reboot, the host can get reprovisioned if PXE is setup correctly. Data loss. Therefore we MUST error out instead of generating new token asking the user to enter build mode (which creates a new token).

Comment 3 Lukas Zapletal 2021-01-19 10:34:05 UTC
Minor issue, I don't have the capacity to work on this one. I created an upstream bug for this: https://projects.theforeman.org/issues/31673 - feel free to reopen if needed.

Comment 4 Lukas Zapletal 2021-01-19 10:34:29 UTC
Correction, upstream bug: https://projects.theforeman.org/issues/31674

Note You need to log in before you can comment on or make changes to this bug.