Uploaded image for project: 'RHOS Request for Features'
  1. RHOS Request for Features
  2. RHOSRFE-174

Add OpenShift cacert to the TLS cacert bundle

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Normal Normal
    • Security
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • rhos-ops-platform-services-security

      There might exist services (like rsyslog) on the compute nodes that connect back to OpenShift due to the ever-increasing convergence between OSP and OCP.

      These connections must also be TLSe and therefore they need the OpenShift CA cert on the compute node to be able to verify that the issuer is correct.

      The current cacerts-bundle that is being generated by dataplane-operator to send to the compute nodes should include the openshift cacert present in the secret openshift-service-ca/signing-key.

              Unassigned Unassigned
              rhn-engineering-jlarriba Juan Larriba
              rhos-dfg-security
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: