Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-80303

[RHEL-9] Start micro-dnsconfd.service after dumping CA certificates

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Undefined Undefined
    • rhel-9.6
    • rhel-9.6
    • anaconda
    • None
    • anaconda-34.25.5.17-1.el9_6
    • No
    • Important
    • rhel-anaconda
    • 28
    • 29
    • 3
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • None
    • Approved Blocker
    • Unspecified Release Note Type - Unknown
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      What were you trying to do that didn't work?

      Hostname resolution using encrypted DNS doesn't work in the installer when custom CA certificates are provided in the kickstart file. This is caused by the micro-dnsconfd service started before the CA certificates from the kickstart file are stored in the filesystem.

      What is the impact of this issue to you?

      Unable to use encrypted DNS in the installer when using custom CA certificates.

      Please provide the package NVR for which the bug is seen:

      anaconda-40.22.3.25-1.el10

      How reproducible is this bug?:

      Always

      Steps to reproduce

      1. Have a kickstart file with the %certificate section containing the eDNS CA certificates.
      2.  Start the installation, add necessary boot options pointing to an encrypted DNS server. (rd.net.dns=dns+tls://... rd.net.dns-backend=dnsconfd).

      Expected results

      It's possible to resolve hostnames using the encrypted DNS server and provided CA certificates.

      Actual results

      DNS resolution doesn't work in the installer.

              rvykydal@redhat.com Radek Vykydal
              jstodola@redhat.com Jan Stodola
              anaconda-maint-list anaconda-maint-list
              Release Test Team Release Test Team
              Sagar Dubewar Sagar Dubewar
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: