Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-3022

Issue SSL certificates for ovsdb-server AF_INET clients

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • None

      AF_INET ovsdb-server sockets may be exposed to unauthorized clients unless guarded by SSL certificates. To be able to safely switch to AF_INET for ovsdb-server communication for all its clients (configJob, ovn-controller, ovs-vswitchd), we should generate and inject SSL certificates for the server and its clients' containers.

       

      Communication paths to cover:

      • ovsdb-server to ovn-controller
      • ovsdb-server to ovs-vswitchd
      • ovsdb-server to configJob spawn by OVNController controller

              Unassigned Unassigned
              ihrachys Ihar Hrachyshka
              rhos-dfg-networking-squad-neutron
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: