Bug 1902101 - [FFU OSP13 to 16.1] TLS upgrade of compute fails
Summary: [FFU OSP13 to 16.1] TLS upgrade of compute fails
Keywords:
Status: CLOSED DUPLICATE of bug 1901157
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: python-novajoin
Version: 13.0 (Queens)
Hardware: Unspecified
OS: Unspecified
unspecified
urgent
Target Milestone: ---
: ---
Assignee: Ade Lee
QA Contact: Jeremy Agee
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-11-26 22:47 UTC by camorris@redhat.co
Modified: 2024-03-25 17:16 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2020-11-27 07:52:10 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Knowledge Base (Solution) 5581281 0 None None None 2020-11-26 23:16:33 UTC

Description camorris@redhat.co 2020-11-26 22:47:22 UTC
Description of problem:
Running openstack overcloud upgrade run -y --stack overcloud --limit compute-0-ffu.    

Version-Release number of selected component (if applicable):
OSP13
rhel-8.2+ osp16.1

How reproducible:
Everytime

Steps to Reproduce:
1. openstack overcloud upgrade run -y --stack overcloud --limit compute-0-ffu

Actual results:
The command fails

Expected results:
The command succeeds.

Additional info:
Nov 17 08:37:57 compute-0-ffu certmonger[38078]: Certificate in file "/etc/pki/libvirt-vnc/server-cert.pem" issued by CA and saved.
Nov 17 08:37:57 compute-0-ffu puppet-user[37753]: Notice: /Stage[main]/Tripleo::Profile::Base::Certmonger_user/Tripleo::Certmonger::Qemu[qemu-nbd-client-cert]/Certmonger_certificate[qemu-nbd-client-cert]/ensure: created
Nov 17 08:37:57 compute-0-ffu ansible-async_wrapper.py[37731]: 37732 still running (3590)
Nov 17 08:37:58 compute-0-ffu certmonger[2544]: Submitting request to "https://freeipa.nodel8.local/ipa/xml".
Nov 17 08:37:59 compute-0-ffu certmonger[2544]: Fault 2100: (RPC failed at server.  Insufficient access: Insufficient 'add' privilege to add the entry 'krbprincipalname=qemu/compute-0-ffu.internalapi.nodel8.local,cn=services,cn=accounts,dc=nodel8,dc=local'.).
Nov 17 08:37:59 compute-0-ffu certmonger[2544]: 2020-11-17 08:37:59 [2544] Server at https://freeipa.nodel8.local/ipa/xml denied our request, giving up: 2100 (RPC failed at server.  Insufficient access: Insufficient 'add' privilege to add the entry 'krbprincipalname=qemu/compute-0-ffu.internalapi.nodel8.local,cn=services,cn=accounts,dc=nodel8,dc=local'.).
Nov 17 08:37:59 compute-0-ffu certmonger[38098]: Request for certificate to be stored in file "/etc/pki/libvirt-nbd/client-cert.pem" rejected by CA.
Nov 17 08:37:59 compute-0-ffu puppet-user[37753]: Warning: Could not get certificate: Execution of '/usr/bin/getcert request -I qemu-nbd-client-cert -f /etc/pki/libvirt-nbd/client-cert.pem -c IPA -N CN=compute-0-ffu.internalapi.nodel8.local -K qemu/compute-0-ffu.internalapi.nodel8.local -D compute-0-ffu.internalapi.nodel8.local -w -k /etc/pki/libvirt-nbd/client-key.pem -F /etc/pki/CA/certs/qemu.pem' returned 2: New signing request "qemu-nbd-client-cert" added.
Nov 17 08:37:59 compute-0-ffu kernel: IPv4: martian source 10.204.221.142 from 10.204.221.131, on dev eno2
Nov 17 08:37:59 compute-0-ffu kernel: ll header: 00000000: ff ff ff ff ff ff 0c c4 7a 32 09 f8 08 06        ........z2....
Nov 17 08:37:59 compute-0-ffu puppet-user[37753]: Error: /Stage[main]/Tripleo::Profile::Base::Certmonger_user/Tripleo::Certmonger::Qemu[qemu-nbd-client-cert]/Certmonger_certificate[qemu-nbd-client-cert]: Could not evaluate: Could not get certificate: Server at https://freeipa.nodel8.local/ipa/xml denied our request, giving up: 2100 (RPC failed at server.  Insufficient access: Insufficient 'add' privilege to add the entry 'krbprincipalname=qemu/compute-0-ffu.internalapi.nodel8.local,cn=services,cn=accounts,dc=nodel8,dc=local'.).
Nov 17 08:37:59 compute-0-ffu puppet-user[37753]: Notice: /Stage[main]/Tripleo::Profile::Base::Certmonger_user/Tripleo::Certmonger::Qemu[qemu-nbd-client-cert]/File[/etc/pki/libvirt-nbd/client-cert.pem]: Dependency Certmonger_certificate[qemu-nbd-client-cert] has failures: true
Nov 17 08:37:59 compute-0-ffu puppet-user[37753]: Warning: /Stage[main]/Tripleo::Profile::Base::Certmonger_user/Tripleo::Certmonger::Qemu[qemu-nbd-client-cert]/File[/etc/pki/libvirt-nbd/client-cert.pem]: Skipping because of failed dependencies
Nov 17 08:37:59 compute-0-ffu puppet-user[37753]: Warning: /Stage[main]/Tripleo::Profile::Base::Certmonger_user/Tripleo::Certmonger::Qemu[qemu-nbd-client-cert]/File[/etc/pki/libvirt-nbd/client-key.pem]: Skipping because of failed dependencies
Nov 17 08:37:59 compute-0-ffu puppet-user[37753]: Notice: /Stage[main]/Tripleo::Profile::Base::Certmonger_user/Tripleo::Certmonger::Qemu[qemu-server-cert]/Certmonger_certificate[qemu-server-cert]/ensure: created

Comment 2 Michele Baldessari 2020-11-27 07:52:10 UTC

*** This bug has been marked as a duplicate of bug 1901157 ***


Note You need to log in before you can comment on or make changes to this bug.