Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1839742 (OCPRHV-83-4.5)

Summary: OCPRHV-83: Installer lets you provide incomplete oVirt CA bundle
Product: OpenShift Container Platform Reporter: Jan Zmeskal <jzmeskal>
Component: InstallerAssignee: Douglas Schilling Landgraf <dougsland>
Installer sub component: OpenShift on RHV QA Contact: Guilherme Santos <gdeolive>
Status: CLOSED ERRATA Docs Contact:
Severity: medium    
Priority: high CC: dougsland
Version: 4.5   
Target Milestone: ---   
Target Release: 4.6.0   
Hardware: Unspecified   
OS: Unspecified   
URL: https://issues.redhat.com/browse/OCPRHV-83
Whiteboard:
Fixed In Version: Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-10-27 16:01:02 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1846366, 1850723    
Bug Blocks:    

Description Jan Zmeskal 2020-05-25 12:10:09 UTC
Description of problem:
openshift-install accepts incomplete oVirt CA bundle and creates ~/.ovirt/ovirt-config.yaml with that wrong payload. If I then run openshift-install create cluster, the installation actually proceeds successfully. Given that the installer uses definitely wrong CA bundle, I must suspect that the communication with oVirt becomes insecure (though I haven't analyzed that). This might be potential vulnerability.

Version-Release number of the following components:
openshift-install-linux-4.5.0-0.nightly-2020-05-25-012559
rhvm-4.3.10.3-0.1.master.el7.noarch

How reproducible:
100 %

Steps to Reproduce:
https://pastebin.com/raw/X6SN3yHP

Actual results:
Installer accepts incomplete oVirt CA bundle, create ovirt-config.yaml with it and proceeds with installation.

Expected results:
Ideal case would be if the installer showed error to the user and prompted that to enter CA bundle content again. However, under no circumstances the installer should start deployment with wrong payload in ovirt-config.yaml unless ovirt_insecure: true is explicitly specified there.

Comment 2 Scott Dodson 2020-06-09 14:38:42 UTC
One bug per PR. Moving this back to ASSIGNED. You may either consolidate bugs into something like "make CA experience less painful" or open multiple PRs.

Comment 5 Guilherme Santos 2020-07-22 13:33:27 UTC
Verified since no input of CA certificate is needed on 4.6 anymore (it download it automatically)

Comment 7 errata-xmlrpc 2020-10-27 16:01:02 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (OpenShift Container Platform 4.6 GA Images), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2020:4196