Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-7809

Allow management of CAs independently from full certificate chains in GitOps

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • None
    • GitOps
    • None
    • None
    • Product / Portfolio Work
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      1. Proposed title of this feature request
      Allow management of CAs independently from full certificate chains
      2. What is the nature and description of the request?
      Currently, when updating trusted certificates across multiple clusters, customers are required to update the entire certificate chain whenever any certificate within the chain changes.
      This feature request proposes the ability to add or update only the certificate signers (Certificate Authorities, or CAs) within the trusted CA configuration, rather than having to replace the full certificate chain each time.
      This would streamline certificate management and reduce operational overhead, particularly in environments with numerous clusters.
      3. Why does the customer need this? (List the business requirements here) * The customer operates 18 clusters, and the current process of updating the full certificate chain for each change is highly resource-intensive and time-consuming.

      • Allowing the addition or update of only CA certificates would significantly reduce maintenance efforts and the risk of configuration errors.

      4. List any affected packages or components.
      Certificates, ArgoCD

              halawren@redhat.com Harriet Lawrence
              rhn-support-disharma Diksha Sharma
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                None
                None