metadata service calls to nova-api-metadata with IP based SAN's fails
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
neutron |
Fix Released
|
Undecided
|
Unassigned | ||
neutron (Ubuntu) |
Fix Released
|
High
|
James Page | ||
Xenial |
Triaged
|
Low
|
Unassigned | ||
Bionic |
Fix Released
|
High
|
Unassigned | ||
Cosmic |
Fix Released
|
High
|
James Page |
Bug Description
[Impact]
If the nova-api-metadata service is secured with a certificate that makes use of IP based SAN's, under Python 2 certificate validation will fail as the ssl module does not support use of IP addresses in cert SAN fields (and httplib2 which is used to make the request uses ssl directly).
Master branch of neutron has switched (see [0]) to using requests to make these calls, supporting use of certs with IP address based SAN's (via urllib3 which does support IP address based SAN's under Python 2).
[0] https:/
[Test Case]
Deploy OpenStack, securing metadata service using certs with IPAddress based SAN's (openstack charms + vault can do this).
Boot instance - instance will fail to get metadata due to neutron->nova cert verification failure.
[Regression Potential]
Patch switches communication between neutron and nova for metadata queries to use requests over httplib2; so its a fairly like-for-like switch - both are used across openstack for various purposes.
Changed in neutron (Ubuntu Cosmic): | |
status: | New → Triaged |
Changed in neutron (Ubuntu Bionic): | |
status: | New → Triaged |
Changed in neutron (Ubuntu Xenial): | |
status: | New → Triaged |
importance: | Undecided → High |
Changed in neutron (Ubuntu Bionic): | |
importance: | Undecided → High |
Changed in neutron (Ubuntu Cosmic): | |
importance: | Undecided → High |
description: | updated |
description: | updated |
Changed in neutron: | |
status: | New → Fix Committed |
Changed in neutron (Ubuntu Cosmic): | |
status: | Triaged → In Progress |
assignee: | nobody → James Page (james-page) |
Changed in neutron (Ubuntu Xenial): | |
importance: | High → Low |
description: | updated |
description: | updated |
tags: | added: neutron-proactive-backport-potential |
tags: | removed: neutron-proactive-backport-potential |
Changed in neutron: | |
status: | Fix Committed → Fix Released |
Fix proposed to branch: stable/rocky /review. openstack. org/599537
Review: https:/