compute node: neutron-ovn-metadata-agent: ovn-sb SSL certificates are not configured

Bug #1976315 reported by Max Khon
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
MicroStack
New
Undecided
Unassigned

Bug Description

SSL certificates are not configured for neutron-ovn-metadata-agent (ovn-sb).
As a result ovn-sb can not connect to ovn-ovsdb-server:

On control node:

# journalctl -u snap.microstack.ovn-ovsdb-server-sb -l --no-page

5 31 07:03:22 eq-os1 ovsdb-server[35642]: ovs|00299|stream_ssl|WARN|SSL_accept: system error (Success)
5 31 07:03:22 eq-os1 ovsdb-server[35642]: ovs|00300|jsonrpc|WARN|Dropped 2 log messages in last 64 seconds (most recently, 64 seconds ago) due to excessive rate
5 31 07:03:22 eq-os1 ovsdb-server[35642]: ovs|00301|jsonrpc|WARN|ssl:10.30.0.13:58894: receive error: Protocol error
5 31 07:03:22 eq-os1 ovsdb-server[35642]: ovs|00302|reconnect|WARN|ssl:10.30.0.13:58894: connection dropped (Protocol error)
5 31 07:03:22 eq-os1 ovsdb-server[35642]: ovs|00303|stream_ssl|WARN|SSL_accept: system error (Success)
5 31 07:03:22 eq-os1 ovsdb-server[35642]: ovs|00304|jsonrpc|WARN|ssl:10.30.0.13:58896: receive error: Protocol error
5 31 07:03:22 eq-os1 ovsdb-server[35642]: ovs|00305|reconnect|WARN|ssl:10.30.0.13:58896: connection dropped (Protocol error)
5 31 07:03:22 eq-os1 ovsdb-server[35642]: ovs|00306|stream_ssl|WARN|SSL_accept: system error (Success)
5 31 07:03:22 eq-os1 ovsdb-server[35642]: ovs|00307|jsonrpc|WARN|ssl:10.30.0.13:58898: receive error: Protocol error

Workaround:

On compute node: append the following configuration keys to [ovn] section of /var/snap/microstack/common/etc/neutron/neutron_ovn_metadata_agent.ini:

---
ovn_sb_private_key = /var/snap/microstack/common/etc/ssl/private/compute-key.pem
ovn_sb_certificate = /var/snap/microstack/common/etc/ssl/certs/compute-cert.pem
ovn_sb_ca_cert = /var/snap/microstack/common/etc/ssl/certs/cacert.pem
---

And restart snap.microstack.neutron-ovn-metadata-agent service:

# systemctl restart snap.microstack.neutron-ovn-metadata-agent

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.