Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-60495

Invalid target signer validity is preventing from issuing node-system-admin-client for 2 years

XMLWordPrintable

    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • In Progress
    • Bug Fix
    • Hide
      Before this update, a limitation prevented a certificate's validity from exceeding that of the signer. This impacted the localhost-recovery.kubeconfig file, as the node-system-admin-client certificate was incorrectly generated with a one-year lifespan instead of the intended two years, causing the premature expiration of the kubeconfig. With this release, the signer certificate's validity is exteneded to three years, ensuring the node-system-admin-client certificate now has a two-year lifespan. (link:https://issues.redhat.com/browse/OCPBUGS-60595[OCPBUGS-55783])
      Show
      Before this update, a limitation prevented a certificate's validity from exceeding that of the signer. This impacted the localhost-recovery.kubeconfig file, as the node-system-admin-client certificate was incorrectly generated with a one-year lifespan instead of the intended two years, causing the premature expiration of the kubeconfig. With this release, the signer certificate's validity is exteneded to three years, ensuring the node-system-admin-client certificate now has a two-year lifespan. (link: https://issues.redhat.com/browse/OCPBUGS-60595 [ OCPBUGS-55783 ])
    • None
    • None
    • None
    • None

      This is a clone of issue OCPBUGS-59527. The following is the description of the original issue:

      Description of problem:

          Target cert validity cannot be longer than signer validity. As a result, node-system-admin-client cannot be issued for 2 years as node-system-admin-signer is valid for 1 year only.
      Signer validity should be extended to 3 years (and refreshed at 2.5 years)

      Version-Release number of selected component (if applicable):

          

      How reproducible:

          

      Steps to Reproduce:

          1.
          2.
          3.
          

      Actual results:

          

      Expected results:

          

      Additional info:

          

              vrutkovs@redhat.com Vadim Rutkovsky
              vrutkovs@redhat.com Vadim Rutkovsky
              None
              None
              Ke Wang Ke Wang
              None
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: