Adds the ability to provide user certificates to HAProxy

Bug #1494109 reported by OpenStack Infra
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack-Ansible
Fix Released
Low
Major Hayden

Bug Description

https://review.openstack.org/221667
commit 68b14d6e81ec541d8dc850ae41eb737862f640e0
Author: Jean-Philippe Evrard <email address hidden>
Date: Fri Aug 21 11:05:07 2015 +0200

    Adds the ability to provide user certificates to HAProxy

    This change brings similar changes as this one targeting horizon:

    i.e.:
    * The server key/certificate (and optionally a CA cert) are
      distributed to all haproxy containers.

    * Two new variables have been implemented for a user-provided
      server key and certificate:
      - haproxy_user_ssl_cert: <path to cert on deployment host>
      - haproxy_user_ssl_key: <path to cert on deployment host>
      If either of these is not defined, then the missing cert/key
      will be self generated on each container. No distribution
      of the self generated certificates accross all the hosts
      is planned.

    * A new variable has been implemented for a user-provided CA
      certificate:
      - haproxy_user_ssl_ca_cert: <path to cert on deployment host>

    * The 'haproxy_cert_regen' variable has been renamed
      to 'haproxy_ssl_self_signed_regen' to have the same
      naming convention as horizon.

    * A change of certificates, whether user dropped
      or role generated, triggers pem generation and server restart

    DocImpact
    Closes-Bug: #1487380

    Change-Id: I0c88d197d8ede820ac4e0388e67a2da06b003c2b
    (cherry picked from commit 422a5b1e0fde667e7e9e7dd66bd3a8c6f2b9beb3)

Changed in openstack-ansible:
status: New → Confirmed
importance: Undecided → Low
assignee: nobody → RPC Documentation (rpcdocs)
Changed in openstack-ansible:
assignee: RPC Documentation (rpcdocs) → Major Hayden (rackerhacker)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to openstack-ansible (master)

Reviewed: https://review.openstack.org/275778
Committed: https://git.openstack.org/cgit/openstack/openstack-ansible/commit/?id=a14ec58f4441476a07a41fa23f28760dfc65ade6
Submitter: Jenkins
Branch: master

commit a14ec58f4441476a07a41fa23f28760dfc65ade6
Author: Major Hayden <email address hidden>
Date: Wed Feb 3 09:51:32 2016 -0600

    Docs: Add HAProxy SSL configuration options

    Closes-bug: 1494109

    Change-Id: I5ea6858868bd2a7393cf364b32f488e198795906

Changed in openstack-ansible:
status: Confirmed → Fix Released
Revision history for this message
Davanum Srinivas (DIMS) (dims-v) wrote : Fix included in openstack/openstack-ansible 13.0.0

This issue was fixed in the openstack/openstack-ansible 13.0.0 release.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.