Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-114237

[RFE] [nmstate] Support rightca in ipsec section

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • None
    • nmstate
    • None
    • None
    • rhel-net-mgmt
    • 3
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • Hide

      Definition of Done:

      Please mark each item below with ( / ) if completed or ( x ) if incomplete:

      ( ) The acceptance criteria defined below are met.

      Given a valid nmstate YAML with IPsec interface including the rightca option, 

      When they sysadmin applies the state via `nmstatectl apply --no-commit`,

      Then the configuration is accepted without error and the `rightca` parameter is correctly passed to NetworkManager and `nmstatectl show` reflects the `rightca` field under the applied IPsec interface. 


      ( ) Integration test case is available upstream.


      ( ) Code is reviewed and merged upstream.


      ( ) Preliminary testing is done.


      ( ) Upstream documentation is written in the upstream MR.


      ( ) Release notes text is written in the RHEL issue.


      ( ) A demo is recorded

      Show
      Definition of Done: Please mark each item below with ( / ) if completed or ( x ) if incomplete: ( ) The acceptance criteria defined below are met. Given a valid nmstate YAML with IPsec interface including the rightca option,  When they sysadmin applies the state via `nmstatectl apply --no-commit`, Then the configuration is accepted without error and the `rightca` parameter is correctly passed to NetworkManager and `nmstatectl show` reflects the `rightca` field under the applied IPsec interface.  ( ) Integration test case is available upstream. ( ) Code is reviewed and merged upstream. ( ) Preliminary testing is done. ( ) Upstream documentation is written in the upstream MR. ( ) Release notes text is written in the RHEL issue. ( ) A demo is recorded
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      Goal

      For an IPSEC configuration from Openshift (libreswan) to strongswan we found that rightca parameter could be needed to establish the connection.

      Currently, this cannot be configured with nmstate.

       

       

              nm-team Network Management Team
              rh-ee-mmayeras Mickael Mayeras
              Network Management Team Network Management Team
              Mingyu Shi Mingyu Shi
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated: