Alan Bishop 63111546cd Fix etcd's support for internal TLS
Fixes for etcd's certmonger cert and key generation:
- Do not chown the cert and key files generated on the host. In addition
  to the fact that "etcd" is not a valid user|grep name on the host, an
  ACL must be used to allow other services (such as cinder) to access
  the files. That ACL will be handled at the THT layer.
- New $dnsnames parameter supports adding a list of subject alternative
  name (SAN) to the cert.
- Remove obsolete default $postsave_cmd (see comment in the code), but
  make it a parameter so it can be overridden if necessary.

The cinder-volume service uses etcd when cinder is configured for
active/active mode. When internal TLS is enabled, the backend_url must
include references to etcd's cert and key files.

Partial-Bug: #1869955
Change-Id: Ifa7452ec15b81f48d7e5fb1252f20b5af1dff95c
2020-04-01 09:23:26 -07:00
2018-02-28 14:42:12 +08:00
2020-04-01 09:23:26 -07:00
2019-11-15 12:22:02 +00:00
2020-03-25 11:10:20 +09:00
2019-04-19 19:35:27 +00:00
2020-02-13 12:25:04 -05:00
2020-02-08 19:07:34 +09:00
2017-01-25 19:32:31 +00:00
2018-06-27 22:47:34 +08:00
2017-10-06 12:28:56 -07:00
2018-10-16 11:40:19 +08:00

Team and repository tags

Team and repository tags

puppet-tripleo

Lightweight composition layer for Puppet TripleO.

Contributing

Description
RETIRED, Lightweight composition layer for Puppet TripleO
Readme 63 MiB