Add ability to deploy custom CA certificates

Bug #1649844 reported by Adrien Cunin
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack-Ansible
Fix Released
Wishlist
Unassigned

Bug Description

This is a wishlist bug, it'd be nice if OSA could deploy custom CA certificates (specified by the user through user_variables.yml) onto all hosts (bare metal and LXC containers) and configure them to be trusted system-wide.

Here is an example use case:
I configure the Keystone service to use and LDAP backend and connect to it through SSL. The LDAP server uses an SSL certificated issued by a custom CA. I therefore need that custom CA to be trusted by my Keystone containers.

Changed in openstack-ansible:
status: New → Confirmed
importance: Undecided → Wishlist
Revision history for this message
Jean-Philippe Evrard (jean-philippe-evrard) wrote :

See conversation here:

http://eavesdrop.openstack.org/irclogs/%23openstack-ansible/%23openstack-ansible.2016-12-20.log.html#t2016-12-20T16:17:40

Basically it's deployer's work to handle this.
We could improve our documentation, and we could have helper playbooks in the ops repo, but this isn't mandatory to ship as part of OSA.

Revision history for this message
Travis Truman (travis-truman) wrote :

We use https://github.com/Oefenweb/ansible-ca-certificates to take care of this today. I agree that this functionality should not be part of OpenStack-Ansible

Revision history for this message
Adrien Cunin (adri2000) wrote :

This has been possible for quite some time now, via the
openstack_host_ca_certificates variable.

Changed in openstack-ansible:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.