Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-34721

Incorrect usage of install-config.yaml additionalTrustBundle field

XMLWordPrintable

    • Important
    • No
    • Rejected
    • False
    • Hide

      None

      Show
      None
    • Hide
      * Previously, when using the Agent-based installation program in a disconnected environment, unnecessary certificates were added to the CA trust bundle. With this update, the CA bundle ConfigMap only contains CAs explicitly specified by the user. (link:https://issues.redhat.com/browse/OCPBUGS-34721[*OCPBUGS-34721*])
      Show
      * Previously, when using the Agent-based installation program in a disconnected environment, unnecessary certificates were added to the CA trust bundle. With this update, the CA bundle ConfigMap only contains CAs explicitly specified by the user. (link: https://issues.redhat.com/browse/OCPBUGS-34721 [* OCPBUGS-34721 *])
    • Bug Fix
    • In Progress

      This is a clone of issue OCPBUGS-32042. The following is the description of the original issue:

      Description of problem:

      When the user configures the install-config.yaml additionalTrustBundle field (for example, in a disconnected installation using a local registry),
      the user-ca-bundle configmap gets populated with more content than strictly required

      Version-Release number of selected component (if applicable):

          

      How reproducible:

      Always

      Steps to Reproduce:

          1. Setup a local registry and mirror the content of an ocp release
          2. Configure the install-config.yaml for a mirrored installation. In particular, configure the additionalTrustBundle field with the registry cert
          3. Create the agent ISO, boot the nodes and wait for the installation to complete
          

      Actual results:

          The user-ca-bundle cm does not contain onyl the registry cert

      Expected results:

      user-ca-bundle configmap with just the content of the install-config additionalTrustBundle field

      Additional info:

           

              zabitter Zane Bitter
              openshift-crt-jira-prow OpenShift Prow Bot
              Biagio Manzari Biagio Manzari
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: