-
Bug
-
Resolution: Done-Errata
-
Undefined
-
None
-
4.16.0
-
None
-
No
-
False
-
Description of problem:
Customer has no method to revoke break-glass signer certificate for HCP.
Version-Release number of selected component (if applicable):
4.16.0
How reproducible:
always
Steps to Reproduce:
1. not possible
Actual results:
nothing
Expected results:
expected a path to do this
Additional info:
In order to use the new flow introduced to fix this, create a CertificateRevocationRequest in the namespace of a HostedControlPlane as described in the test:
- create a private key, certificate and certificate signing request using e.g. openssl
- create admin credentials for the cluster by using a CertificateSigningRequest and {{CertificateSigningRequestApproval }}{{
}} - revoke the break-glass signing certificate using the CertificateRevocationRequest
- wait for the CRR status to show that it succeeded
- ensure that the credentials created in step 2 are no longer valid
- blocks
-
OCPBUGS-29303 No Functionality Exists To Revoke Break-Glass Signer Certificates
- Closed
- is cloned by
-
OCPBUGS-29303 No Functionality Exists To Revoke Break-Glass Signer Certificates
- Closed
- links to
-
RHEA-2024:0041 OpenShift Container Platform 4.16.z bug fix update