Adds the ability to provide user certificates to HAProxy

Bug #1492091 reported by OpenStack Infra
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack-Ansible
Fix Released
Low
Major Hayden

Bug Description

https://review.openstack.org/215525
commit 422a5b1e0fde667e7e9e7dd66bd3a8c6f2b9beb3
Author: Jean-Philippe Evrard <email address hidden>
Date: Fri Aug 21 11:05:07 2015 +0200

    Adds the ability to provide user certificates to HAProxy

    This change brings similar changes as this one targeting horizon:

    i.e.:
    * The server key/certificate (and optionally a CA cert) are
      distributed to all haproxy containers.

    * Two new variables have been implemented for a user-provided
      server key and certificate:
      - haproxy_user_ssl_cert: <path to cert on deployment host>
      - haproxy_user_ssl_key: <path to cert on deployment host>
      If either of these is not defined, then the missing cert/key
      will be self generated on each container. No distribution
      of the self generated certificates accross all the hosts
      is planned.

    * A new variable has been implemented for a user-provided CA
      certificate:
      - haproxy_user_ssl_ca_cert: <path to cert on deployment host>

    * The 'haproxy_cert_regen' variable has been renamed
      to 'haproxy_ssl_self_signed_regen' to have the same
      naming convention as horizon.

    * A change of certificates, whether user dropped
      or role generated, triggers pem generation and server restart

    DocImpact
    Closes-Bug: #1487380

    Change-Id: I0c88d197d8ede820ac4e0388e67a2da06b003c2b

Changed in openstack-ansible:
importance: Undecided → Low
status: New → Confirmed
assignee: nobody → RPC Documentation (rpcdocs)
Changed in openstack-ansible:
assignee: RPC Documentation (rpcdocs) → Major Hayden (rackerhacker)
status: Confirmed → In Progress
Revision history for this message
Major Hayden (rackerhacker) wrote :
Changed in openstack-ansible:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.