Uploaded image for project: 'AMQ Streams'
  1. AMQ Streams
  2. ENTMQST-4818

[FIPS] Certificate renewal is not working properly on OCP FIPS clusters

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Blocker Blocker
    • 2.4.0.GA
    • 2.4.0.GA
    • None
    • None

      It seems that the force certificate renewal is not working on the OCP clusters with FIPS enabled.
      Renewal is triggered by strimzi.io/force-replace.
      The resources - Kafka, ZK, EO - should do three rolls to renew their certificates, the two rolls are executed without a problem, but the third roll is not completely finished and CO contains errors (the attachment contains the full operator log).

      The issue was discovered by test in `SecurityST#testAutoReplaceAllCaKeysTriggeredByAnno`.

        1. co.log
          5.40 MB
          Lukas Kral

              Unassigned Unassigned
              lkral Lukas Kral
              Jakub Stejskal Jakub Stejskal
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: