Add statement to remind users to lock/unlock controller nodes after installing a ssl_ca

Bug #1995145 reported by Juanita-Balaraj
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
StarlingX
Fix Released
Medium
Juanita-Balaraj

Bug Description

Brief Description
-----------------
Add statement to remind users to lock/unlock controller nodes after installing a ssl_ca.

Severity
--------
Provide the severity of the defect.
<Minor: System/Feature is usable with minor issue>

Steps to Reproduce
------------------
https://docs.starlingx.io/security/kubernetes/configure-oidc-auth-applications.html
Note: it is necessary to ensure the system trusts the CA.  The gist of the text can be copied from section 1. b. Prerequisites "If a signing CA  is not a well-known trusted CA, you must ensure the system trusts the CA by specifying it either during the bootstrap phase of system installation, by specifying ssl_ca_cert: <certificate_file> in the ansible bootstrap overrides localhost.yml file, or by using the system certificate-install -m ssl_ca <certificate_file> command."

And append the sentence "Also refer to https://docs.starlingx.io/security/kubernetes/add-a-trusted-ca.html for installing a root CA, which includes instruction to lock/unlock controller nodes when using 'system certificate-install' command.
This last sentence can also be appended to section 1. b. Prerequisites, after "or by using the system certificate-install -m ssl_ca dex-ca.pem command."
The document to be changed is in starlingx/docs (https://opendev.org/starlingx/docs.git):
doc/source/security/kubernetes/configure-oidc-auth-applications.rst

Expected Behavior
------------------
Write down what was expected after taking the steps written above

Actual Behavior
----------------
State what is the actual behavior

Reproducibility
---------------
<Reproducible/Intermittent/Seen once>
State if the issue is 100% reproducible, intermittent or seen once. If it is intermittent, state the frequency of occurrence

System Configuration
--------------------
<One node system, Two node system, Multi-node system, Dedicated storage, https, IPv4, IPv6 etc.>

Branch/Pull Time/Commit
-----------------------
Branch and the time when code was pulled or git commit or cengn load info

Last Pass
---------
Did this test scenario pass previously? If so, please indicate the load/pull time info of the last pass.
Use this section to also indicate if this is a new test scenario.

Timestamp/Logs
--------------
Attach the logs for debugging (use attachments in Launchpad or for large collect files use: https://files.starlingx.kube.cengn.ca/)
Provide a snippet of logs here and the timestamp when issue was seen.
Please indicate the unique identifier in the logs to highlight the problem

Test Activity
-------------
[Sanity, Feature Testing, Regression Testing, Developer Testing, Evaluation, Other - Please specify]

Workaround
----------
Describe workaround if available

Changed in starlingx:
status: New → Incomplete
status: Incomplete → Triaged
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to docs (master)

Fix proposed to branch: master
Review: https://review.opendev.org/c/starlingx/docs/+/868146

Changed in starlingx:
status: Triaged → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to docs (master)

Reviewed: https://review.opendev.org/c/starlingx/docs/+/868146
Committed: https://opendev.org/starlingx/docs/commit/cfed9ee0dc21f2b0b27be235757344ca77046772
Submitter: "Zuul (22348)"
Branch: master

commit cfed9ee0dc21f2b0b27be235757344ca77046772
Author: Elaine Fonaro <email address hidden>
Date: Mon Dec 19 20:38:36 2022 -0300

    Add a note users to lock/unlock controller nodes after installing a ssl_ca

    - Added a note for lock/unlock controler node.
    - Added a reference for installing a root CA.

    Closes-bug: 1995145

    Signed-off-by: Elaine Fonaro <email address hidden>
    Change-Id: I293ecc19348308e60da7f5922d169c455b895576

Changed in starlingx:
status: In Progress → Fix Released
Ghada Khalil (gkhalil)
Changed in starlingx:
importance: Medium → Low
tags: added: stx.8.0
Changed in starlingx:
importance: Low → Medium
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.