console not negotiating TLS with certificates provided by vault

Bug #1881368 reported by Seth Tanner
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Nova Cloud Controller Charm
Expired
Undecided
Unassigned

Bug Description

The web browser shows: Secure Connection Failed

$ tail -f /var/log/nova/nova-novncproxy.log
2020-05-29 21:10:50.484 107783 INFO nova.console.websocketproxy [-] WebSocket server settings:
2020-05-29 21:10:50.484 107783 INFO nova.console.websocketproxy [-] - Listen on 0.0.0.0:6080
2020-05-29 21:10:50.485 107783 INFO nova.console.websocketproxy [-] - Web server (no directory listings). Web root: /usr/share/novnc
2020-05-29 21:10:50.485 107783 INFO nova.console.websocketproxy [-] - SSL/TLS support
2020-05-29 21:10:50.486 107783 INFO nova.console.websocketproxy [-] - proxying from 0.0.0.0:6080 to None:None
2020-05-29 21:12:37.930 109375 INFO nova.console.websocketproxy [-] handler exception: wrap_socket() got an unexpected keyword argument '_context'

$ openssl s_client -connect nova-cloud-controller:6080
CONNECTED(00000003)
write:errno=54
---
no peer certificate available
---
No client certificate CA names sent
---
SSL handshake has read 0 bytes and written 307 bytes
---
New, (NONE), Cipher is (NONE)
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
    Protocol : TLSv1.2
    Cipher : 0000
    Session-ID:
    Session-ID-ctx:
    Master-Key:
    Key-Arg : None
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    Start Time: 1590801024
    Timeout : 300 (sec)
    Verify return code: 0 (ok)

Seth Tanner (sjtanner)
summary: - console running TLS with vault
+ console not negotiating TLS with certificates provided by vault
Revision history for this message
Alex Kavanagh (ajkavanagh) wrote :

This bug is now 3 years old; setting to incomplete - it will expire in 60 days unless reset to new. If this issue still persists, please reset the bug to new and add additional supporting information.

Changed in charm-nova-cloud-controller:
status: New → Incomplete
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for OpenStack Nova Cloud Controller Charm because there has been no activity for 60 days.]

Changed in charm-nova-cloud-controller:
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.