distcloud/distributedcloud/dcorch
Jessica Castelino 4f1c5db809 Sync only ‘ssl_ca’ and ‘openstack_ca’ certificates to subclouds
The 'docker_registry', 'tpm_mode', and 'openstack' cert on the
SystemController will have a CN and SAN with OAM IP Address, any
related DNS Names for OAM IP Address and MGMT IP Address. If these
certificate are synched to the subclouds, even if they are signed by
a trusted CA, when any client connects to the subcloud OAM or MGMT
IP, the certificate that comes back will not pass certificate
validation because the certificate does not apply to the subcloud's
IP Address. For this reason a fix is put in place to avoid only sync
"ssl_ca" and "openstack_ca" certificates to subclouds.

Change-Id: I17ac94d79beb04f559c46062dbe7826590fcdb06
Signed-off-by: Jessica Castelino <jessica.castelino@windriver.com>
Closes-Bug: 1865643
2020-07-02 13:31:46 -04:00
..
api Distributed Cloud re-execution susceptible to old data 2020-06-23 16:44:19 -04:00
cmd Extend sysinv api proxy to support load operations 2020-06-01 16:16:20 -04:00
common Merge "Configure dcmanager user for endpoint_cache" 2020-06-19 13:53:58 +00:00
db Prevent unlimited growth of dcorch database 2020-04-30 10:55:12 -04:00
drivers Keystone token and resource caching 2020-03-23 21:31:04 -04:00
engine Sync only ‘ssl_ca’ and ‘openstack_ca’ certificates to subclouds 2020-07-02 13:31:46 -04:00
objects Prevent unlimited growth of dcorch database 2020-04-30 10:55:12 -04:00
rpc Move subcloud audit to separate process 2020-05-14 09:34:23 -05:00
tests Prevent unlimited growth of dcorch database 2020-04-30 10:55:12 -04:00
__init__.py Move content to subdir to support relocated packaging 2019-11-04 13:57:02 -05:00
config-generator.conf Move content to subdir to support relocated packaging 2019-11-04 13:57:02 -05:00
version.py Move content to subdir to support relocated packaging 2019-11-04 13:57:02 -05:00