← Back to team overview

yahoo-eng-team team mailing list archive

[Bug 1790598] Re: metadata service calls to nova-api-metadata with IP based SAN's fails

 

This bug was fixed in the package neutron - 2:13.0.0-0ubuntu2

---------------
neutron (2:13.0.0-0ubuntu2) cosmic; urgency=medium

  * d/p/metadata-use-requests-for-comms-with-nova-api.patch: Cherry
    pick of fix to support use of certs with IP based SAN's on Nova
    API endpoints when making metadata service calls (LP: #1790598).
  * d/control: Bump minimum requests version inline with above patch.

 -- James Page <james.page@xxxxxxxxxx>  Tue, 04 Sep 2018 14:59:36 +0100

** Changed in: neutron (Ubuntu Cosmic)
       Status: In Progress => Fix Released

-- 
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to neutron.
https://bugs.launchpad.net/bugs/1790598

Title:
  metadata service calls to nova-api-metadata with IP based SAN's fails

Status in neutron:
  Fix Committed
Status in neutron package in Ubuntu:
  Fix Released
Status in neutron source package in Xenial:
  Triaged
Status in neutron source package in Bionic:
  Triaged
Status in neutron source package in Cosmic:
  Fix Released

Bug description:
  If the nova-api-metadata service is secured with a certificate that
  makes use of IP based SAN's, under Python 2 certificate validation
  will fail as the ssl module does not support use of IP addresses in
  cert SAN fields (and httplib2 which is used to make the request uses
  ssl directly).

  Master branch of neutron has switched (see [0]) to using requests to
  make these calls, supporting use of certs with IP address based SAN's
  (via urllib3 which does support IP address based SAN's under Python
  2).

  [0]
  https://github.com/openstack/neutron/commit/7e0dd2f18d4919964655cfce7a282d1c5c131fc4

To manage notifications about this bug go to:
https://bugs.launchpad.net/neutron/+bug/1790598/+subscriptions


References