Uploaded image for project: 'Apache Ozone'
  1. Apache Ozone
  2. HDDS-7355

non-primordial scm fail to get signed cert from primordial SCM when converting an unsecure cluster to secure

    XMLWordPrintableJSON

Details

    Description

      when converting a unsecure cluster to a secure one, we need to reinit the primordial SCM to generate the root ca and a sub ca to itself. then , we need to bootstrap the other two scm to get a signed cert and sub ca from primordial SCM.

      current code has a bug in initializeSecurityIfNeeded which will lead the bootstrapped scm to get a self signed cert from itself, not the root signed cert from primordial SCM.

      Attachments

        Issue Links

          Activity

            People

              jacksonyao Jie Yao
              jacksonyao Jie Yao
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: