Add support for supplying a trusted CA certificate file

Registered by Scott Solkhon

Add functionality for an operator to specify their own trusted CA certificate file for interacting with the Keystone API.

Blueprint information

Status:
Complete
Approver:
None
Priority:
Medium
Drafter:
Scott Solkhon
Direction:
Approved
Assignee:
Scott Solkhon
Definition:
Approved
Series goal:
Accepted for train
Implementation:
Implemented
Milestone target:
milestone icon 9.0.0
Started by
Mark Goddard
Completed by
Mark Goddard

Related branches

Sprints

Whiteboard

Gerrit topic: https://review.opendev.org/#/q/topic:bp/support-trusted-ca-certificate-file

Addressed by: https://review.opendev.org/676709
    Support configuration of trusted CA certificate file

Gerrit topic: https://review.opendev.org/#/q/topic:bp/add-ssl-internal-network/reference-cacerts

Addressed by: https://review.opendev.org/699312
    Configure services to use Certificate Authority

Gerrit topic: https://review.opendev.org/#/q/topic:bp/add-ssl-internal-network/copy-cacerts

Addressed by: https://review.opendev.org/699888
    Copy CA into containers.

Gerrit topic: https://review.opendev.org/#/q/topic:bp/add-internal-network/execute-rest-in-container

Addressed by: https://review.opendev.org/700788
    Delegate executing uri REST methods to the current module containers using kolla_toolbox. This will allow self signed certificate that are already copied into the container to be automatically validated. This circumvents requiring Kolla Ansible to explici

Gerrit topic: https://review.opendev.org/#/q/topic:bp/add-internal-network/configure-cacert-verification

Addressed by: https://review.opendev.org/701056
    Configure disabling verification of CA certificates.

Gerrit topic: https://review.opendev.org/#/q/topic:bp/add-internal-network/tls-zuul-tests

Addressed by: https://review.opendev.org/701260
    CI: Add TLS tests

Gerrit topic: https://review.opendev.org/#/q/topic:bp/add-internal-network/generate-certs

Addressed by: https://review.opendev.org/701297
    Generate self signed TLS certificates

Gerrit topic: https://review.opendev.org/#/q/topic:bp/add-internal-network/generate-certificates

Addressed by: https://review.opendev.org/701302
    Generate self signed TLS certificates

Gerrit topic: https://review.opendev.org/#/q/topic:bp/add-internal-network/configure-certs

Addressed by: https://review.opendev.org/701323
    Generate self signed TLS certificates

Gerrit topic: https://review.opendev.org/#/q/topic:bp/add-internal-network/zuul-tls-test

Addressed by: https://review.opendev.org/701414
    CI: Add TLS tests

(?)

Work Items

This blueprint contains Public information 
Everyone can see this information.

Subscribers

No subscribers.