-
Bug
-
Resolution: Done
-
Critical
-
None
-
4.13, 4.14
-
None
-
No
-
CLOUD Sprint 234, CLOUD Sprint 235
-
2
-
Proposed
-
False
-
-
N/A
-
Bug Fix
-
Done
Kubernetes 1.27 changes validation of CSR for non-RSA kubelet client/serving CSRs, see https://github.com/kubernetes/kubernetes/issues/109077 and the PR changing https://github.com/kubernetes/kubernetes/pull/111660.
For that reason our machine-config-approver needs to relax the validation in https://github.com/openshift/cluster-machine-approver/blob/d74f42bb37c4130ae1e91819d90ad40a51ec472b/pkg/controller/csr_check.go#L84-L86 such that it appropriately expects the necessary key usage.
- clones
-
OCPBUGS-11225 Relax CSR check due to k8s 1.27 changes
- Closed
- depends on
-
OCPBUGS-11225 Relax CSR check due to k8s 1.27 changes
- Closed
- links to