There are several issues with current tutorial for setting rh-sso as identity provider for OpenShift.
- 5.4.2.1 ca: xpaas.crt tutorial is using x509 template for this therefore makes more sense to use actual OPC cert. -> ca: ca-bundle.crt
- 5.4.2.2 atomic-openshift-master is no longer valid service to restart master...
- User can't actually logout from OCP since it's necessary to set rh-sso logout page correctly on client size... otherwise user stays single signed.... (see docs)