Bug 1949941 - create an information alert about the old-format tokens being unusable starting 4.8
Summary: create an information alert about the old-format tokens being unusable starti...
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: apiserver-auth
Version: 4.7
Hardware: Unspecified
OS: Unspecified
Target Milestone: ---
: 4.7.z
Assignee: Standa Laznicka
QA Contact: pmali
: 1877713 (view as bug list)
Depends On: 1944631
TreeView+ depends on / blocked
Reported: 2021-04-15 12:35 UTC by Standa Laznicka
Modified: 2021-05-19 15:16 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Deprecated Functionality
Doc Text:
In the upcoming OpenShift version (4.8), the old-format OAuth tokens (not prepended by sha256~ prefix) will no longer be usable and noone will be able to create them. If an OpenShift 4.7 cluster contains such old-format OAuth tokens, we now raise an informational alert to notify the administrators of the cluster about this behavior change.
Clone Of:
Last Closed: 2021-05-19 15:16:13 UTC
Target Upstream Version:

Attachments (Terms of Use)
prometheus (59.06 KB, image/png)
2021-05-04 03:20 UTC, pmali
no flags Details

System ID Private Priority Status Summary Last Updated
Github openshift cluster-authentication-operator pull 437 0 None open [4.7] Bug 1949941: add a scraper and an alert to check for old-style tokens 2021-04-27 17:07:25 UTC
Red Hat Product Errata RHBA-2021:1550 0 None None None 2021-05-19 15:16:36 UTC

Description Standa Laznicka 2021-04-15 12:35:17 UTC
Description of problem:
We've removed the ability to create or authenticate with tokens that do not have hashed names.

In 4.7, we need to add an informational alert that this is going to happen.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. manually create a non-hashed access/authorize token in the API and attempt to use it

Actual results:
nothing interesting happens

Expected results:
An information-level alert should be created

Comment 1 Standa Laznicka 2021-04-16 10:54:05 UTC
*** Bug 1877713 has been marked as a duplicate of this bug. ***

Comment 5 pmali 2021-05-04 03:20:20 UTC
Created attachment 1779179 [details]

Comment 6 Siddharth Sharma 2021-05-10 17:58:27 UTC
This bug will be shipped as part of next z-stream release 4.7.11 on May 19th, as 4.7.10 was dropped due to a blocker https://bugzilla.redhat.com/show_bug.cgi?id=1958518.

Comment 10 errata-xmlrpc 2021-05-19 15:16:13 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (OpenShift Container Platform 4.7.11 bug fix update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.