-
Bug
-
Resolution: Duplicate
-
Undefined
-
None
-
4.22
-
None
-
False
-
-
None
-
None
-
Yes
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
(Feel free to update this bug's summary to be more specific.)
Component Readiness has found a potential regression in the following test:
install should succeed: overall
Significant regression detected.
Fishers Exact probability of a regression: 100.00%.
Test pass rate dropped from 100.00% to 92.86%.
Sample (being evaluated) Release: 4.22
Start Time: 2026-01-19T00:00:00Z
End Time: 2026-01-26T08:00:00Z
Success Rate: 92.86%
Successes: 65
Failures: 5
Flakes: 0
Base (historical) Release: 4.21
Start Time: 2025-12-27T00:00:00Z
End Time: 2026-01-26T08:00:00Z
Success Rate: 100.00%
Successes: 270
Failures: 0
Flakes: 0
View the test details report for additional context.
Root Cause The ovn-ipsec-host DaemonSet failed to start on all 6 nodes. All pods are stuck in init container failure with this error: Error adding request extensions defined via -addext duplicate attribute The ovn-keys init container is trying to generate IPsec certificates using an OpenSSL command that has conflicting flags: openssl req -new -text -extensions v3_req \ -addext 'subjectAltName = DNS:...' \ -subj /C=US/O=ovnkubernetes/OU=kind/CN=... \ -key /etc/openvswitch/keys/ipsec-privkey.pem \ -out /etc/openvswitch/keys/ipsec-req.pem The command uses both -extensions v3_req and -addext which causes a duplicate attribute error in the OpenSSL version being used.
Filed by: jialiu@redhat.com
- duplicates
-
OCPBUGS-74401 ovn-ipsec-host creates duplicate openssl attribute
-
- ON_QA
-