Uploaded image for project: 'Satellite'
  1. Satellite
  2. SAT-42114

[SPIKE] Decide on how we want to handle custom certificates for CNV

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • sat-rocket
    • False
    • Satellite Rocket Sprint 15
    • None

      After the changes in https://github.com/theforeman/foreman_kubevirt/pull/180 it's not possible anymore to connect to OCP-V instances with self-signed certs without manually fetching those certs and providing them to Satellite.

      While secure, this is cumbersome to the user.

      Let's find a better flow how we can make it secure while also making it easier for the user.

      Looking at the other CRs we have (VMware, OpenStack – I don't expect to have to provide custom certs for GCE/EC2/Azure), we see:

      Should we do something similar (cert offered on first connection is trusted) for OCP-V?
      What about OpenStack?

              egolov@redhat.com Evgeni Golov
              egolov@redhat.com Evgeni Golov
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: