Skip to content

Commit ac23e6e

Browse files
committed
Bug 1512825 - add mux pod failed for Serial number 02 has already been issued
According to [email protected], to run the "oc adm ca create-server-cert" command line with --signer-serial option, the following changes need to be made. 1. adding --overwrite=false 2. <ca.serial.txt> should contain only [0-9A-F]*. (no trailing newlines are allowed for now) This patch solves 1.
1 parent e5a319c commit ac23e6e

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

roles/openshift_logging/tasks/generate_certs.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
command: >
2020
{{ openshift_client_binary }} adm --config={{ mktemp.stdout }}/admin.kubeconfig ca create-signer-cert
2121
--key={{generated_certs_dir}}/ca.key --cert={{generated_certs_dir}}/ca.crt
22-
--serial={{generated_certs_dir}}/ca.serial.txt --name=logging-signer-test
22+
--serial={{generated_certs_dir}}/ca.serial.txt --name=logging-signer-test --overwrite=false
2323
check_mode: no
2424
when:
2525
- not ca_key_file.stat.exists

roles/openshift_logging/tasks/procure_server_certs.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@
3030
{{ openshift_client_binary }} adm --config={{ mktemp.stdout }}/admin.kubeconfig ca create-server-cert
3131
--key={{generated_certs_dir}}/{{cert_info.procure_component}}.key --cert={{generated_certs_dir}}/{{cert_info.procure_component}}.crt
3232
--hostnames={{cert_info.hostnames|quote}} --signer-cert={{generated_certs_dir}}/ca.crt --signer-key={{generated_certs_dir}}/ca.key
33-
--signer-serial={{generated_certs_dir}}/ca.serial.txt
33+
--signer-serial={{generated_certs_dir}}/ca.serial.txt --overwrite=false
3434
check_mode: no
3535
when:
3636
- cert_info.hostnames is defined

0 commit comments

Comments
 (0)