** Description changed:

  [Impact]
  If the nova-api-metadata service is secured with a certificate that makes use 
of IP based SAN's, under Python 2 certificate validation will fail as the ssl 
module does not support use of IP addresses in cert SAN fields (and httplib2 
which is used to make the request uses ssl directly).
  
  Master branch of neutron has switched (see [0]) to using requests to
  make these calls, supporting use of certs with IP address based SAN's
  (via urllib3 which does support IP address based SAN's under Python 2).
  
  [0]
  
https://github.com/openstack/neutron/commit/7e0dd2f18d4919964655cfce7a282d1c5c131fc4
  
  [Test Case]
+ Deploy OpenStack, securing metadata service using certs with IPAddress based 
SAN's (openstack charms + vault can do this).
+ Boot instance - instance will fail to get metadata due to neutron->nova cert 
verification failure.
  
  [Regression Potential]
+ Minimal; patch accepted into stable/rocky branch upstream and part of the 
Rocky release of OpenStack for Ubuntu.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1790598

Title:
  metadata service calls to nova-api-metadata with IP based SAN's fails

To manage notifications about this bug go to:
https://bugs.launchpad.net/neutron/+bug/1790598/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to