From a0e262e20ce5a111d9c097d9b6c7a7549207aebd Mon Sep 17 00:00:00 2001 From: Juan Antonio Osorio Robles Date: Thu, 28 Mar 2019 07:52:11 +0200 Subject: [PATCH] TLS everywhere: switch Octavia to use DNS entries The entries in the tls-everywhere-endpoints-dns.yaml was wrong for octavia; pointing to IPs instead of DNS. This made the TLS everywhere deployment fail, since it assigns certificates for DNS subjectAltNames. Change-Id: Ic6f0f26c03c443edf1715927a4542245e08567f4 Closes-Bug: #1822035 --- environments/ssl/tls-everywhere-endpoints-dns.yaml | 4 ++-- sample-env-generator/ssl.yaml | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/environments/ssl/tls-everywhere-endpoints-dns.yaml b/environments/ssl/tls-everywhere-endpoints-dns.yaml index 9181d2fe45..1fc8e5839e 100644 --- a/environments/ssl/tls-everywhere-endpoints-dns.yaml +++ b/environments/ssl/tls-everywhere-endpoints-dns.yaml @@ -79,8 +79,8 @@ parameter_defaults: NovaVNCProxyAdmin: {protocol: 'https', port: '6080', host: 'CLOUDNAME'} NovaVNCProxyInternal: {protocol: 'https', port: '6080', host: 'CLOUDNAME'} NovaVNCProxyPublic: {protocol: 'https', port: '13080', host: 'CLOUDNAME'} - OctaviaAdmin: {protocol: 'https', port: '9876', host: 'IP_ADDRESS'} - OctaviaInternal: {protocol: 'https', port: '9876', host: 'IP_ADDRESS'} + OctaviaAdmin: {protocol: 'https', port: '9876', host: 'CLOUDNAME'} + OctaviaInternal: {protocol: 'https', port: '9876', host: 'CLOUDNAME'} OctaviaPublic: {protocol: 'https', port: '13876', host: 'CLOUDNAME'} OpenDaylightAdmin: {protocol: 'https', port: '8081', host: 'CLOUDNAME'} OpenDaylightInternal: {protocol: 'https', port: '8081', host: 'CLOUDNAME'} diff --git a/sample-env-generator/ssl.yaml b/sample-env-generator/ssl.yaml index 52d31f5198..f1f60dc83f 100644 --- a/sample-env-generator/ssl.yaml +++ b/sample-env-generator/ssl.yaml @@ -418,8 +418,8 @@ environments: NovaVNCProxyAdmin: {protocol: 'https', port: '6080', host: 'CLOUDNAME'} NovaVNCProxyInternal: {protocol: 'https', port: '6080', host: 'CLOUDNAME'} NovaVNCProxyPublic: {protocol: 'https', port: '13080', host: 'CLOUDNAME'} - OctaviaAdmin: {protocol: 'https', port: '9876', host: 'IP_ADDRESS'} - OctaviaInternal: {protocol: 'https', port: '9876', host: 'IP_ADDRESS'} + OctaviaAdmin: {protocol: 'https', port: '9876', host: 'CLOUDNAME'} + OctaviaInternal: {protocol: 'https', port: '9876', host: 'CLOUDNAME'} OctaviaPublic: {protocol: 'https', port: '13876', host: 'CLOUDNAME'} OpenDaylightAdmin: {protocol: 'https', port: '8081', host: 'CLOUDNAME'} OpenDaylightInternal: {protocol: 'https', port: '8081', host: 'CLOUDNAME'}