Radosgw does not pull certs for SSL connection to Keystone

Bug #1690826 reported by Michael Skalka
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
Ceph RADOS Gateway Charm
Fix Released
Critical
David Ames
ceph-radosgw (Juju Charms Collection)
Invalid
Undecided
Unassigned

Bug Description

Radosgw does not pull the correct certs from keystone through its relationship before attempting to connect to the keystone service, resulting in charm hook failures: http://pastebin.ubuntu.com/25261905/

Manually adding the cert alleviates the issue. In the environment where we encountered this bug we were able to take the cert from a node running nova-cloud-controller and drop it into /usr/local/share/ca-certificates/ then ran update-ca-certificates, which cleared the issue.

James Hebden (ec0)
tags: added: canonical-bootstack
description: updated
David Ames (thedac)
Changed in ceph-radosgw (Juju Charms Collection):
status: New → Invalid
Changed in charm-ceph-radosgw:
status: New → In Progress
importance: Undecided → Critical
assignee: nobody → David Ames (thedac)
milestone: none → 17.08
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to charm-ceph-radosgw (master)

Fix proposed to branch: master
Review: https://review.openstack.org/498122

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to charm-ceph-radosgw (master)

Reviewed: https://review.openstack.org/498122
Committed: https://git.openstack.org/cgit/openstack/charm-ceph-radosgw/commit/?id=22265186125557a53ae77df8f44d0d93f9cb7db5
Submitter: Jenkins
Branch: master

commit 22265186125557a53ae77df8f44d0d93f9cb7db5
Author: David Ames <email address hidden>
Date: Fri Aug 25 16:30:02 2017 -0700

    Use ApacheSSLContext to enable SSL object storage

    Enable SSL object storage using ApacheSSLContext.

    Change-Id: Id044afc8c07696a5447eb9dc4836470203372090
    Closes-Bug: #1690826
    Closes-Bug: #1708464

Changed in charm-ceph-radosgw:
status: In Progress → Fix Committed
James Page (james-page)
Changed in charm-ceph-radosgw:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.