Re: [Openstack-operators] [OCTAVIA][KOLLA] - Self signed CA/CERTS

2018-08-17 Thread Flint WALRUS
Ok, I’ll have a look at the syslog logs as there was nothing but the 404 inside the agent logs. I’ll not be able to get my hand on my lab until at least the middle of the next week so don’t worry if I’m not coming back to you with my results. It’s not that I solved it, just that I won’t get my

Re: [Openstack-operators] [OCTAVIA][KOLLA] - Self signed CA/CERTS

2018-08-17 Thread Michael Johnson
Yes, the amphora-agent logs to both the amphora-agent.log and syslog in /var/log inside the amphora. Michael On Thu, Aug 16, 2018 at 1:43 PM Flint WALRUS wrote: > > Hi Michael, > > Ok, it was indeed an issue with the create_certificate.sh script for centos > that indeed improperly created the

Re: [Openstack-operators] [OCTAVIA][KOLLA] - Self signed CA/CERTS

2018-08-16 Thread Flint WALRUS
Hi Michael, Ok, it was indeed an issue with the create_certificate.sh script for centos that indeed improperly created the client.pem certificate. However now the amphora is responding with a 404 not found when the worker is trying to post /v0.5/plug/vip/10.1.56.12 I know the amphora and the

Re: [Openstack-operators] [OCTAVIA][KOLLA] - Self signed CA/CERTS

2018-08-14 Thread Flint WALRUS
I’ll try to check the certificate format and make the appropriate change if required or let you know if I’ve got something specific regarding that topic. Kind regards, G. Le mar. 14 août 2018 à 19:52, Flint WALRUS a écrit : > Hi Michael, thanks a lot for your quick response once again! > Le

Re: [Openstack-operators] [OCTAVIA][KOLLA] - Self signed CA/CERTS

2018-08-14 Thread Flint WALRUS
Hi Michael, thanks a lot for your quick response once again! Le mar. 14 août 2018 à 18:21, Michael Johnson a écrit : > Hi there Flint. > > Octavia fully supports using self-signed certificates and we use those > in our gate tests. > We do not allow non-TLS authenticated connections in the code,

Re: [Openstack-operators] [OCTAVIA][KOLLA] - Self signed CA/CERTS

2018-08-14 Thread Michael Johnson
Hi there Flint. Octavia fully supports using self-signed certificates and we use those in our gate tests. We do not allow non-TLS authenticated connections in the code, even for lab setups. This is a configuration issue or certificate file format issue. When the controller is attempting to

[Openstack-operators] [OCTAVIA][KOLLA] - Self signed CA/CERTS

2018-08-14 Thread Flint WALRUS
Hi guys, I continue to work on my Octavia integration using Kolla-Ansible and I'm facing a strange behavior. As for now I'm working on a POC using restricted HW and SW Capacities, I'm facing a strange issue when trying to launch a new load-balancer. When I create a new LB, would it be using CLI