-
Notifications
You must be signed in to change notification settings - Fork 6.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix openssl SAN check on newer versions of OpenSSL #11277
Fix openssl SAN check on newer versions of OpenSSL #11277
Conversation
|
Hi @mhamzahkhan. Thanks for your PR. I'm waiting for a kubernetes-sigs member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
a6344f9
to
68f4082
Compare
`ignore_errors` is not really the correct semantic here. I would rather do one of the following:
- use `failed_when` to define what is an error in this tasks
- put the 2 tasks 'regenerate apiserver' in a `rescue` block to use Ansible builtin mechanisms (also, that would reduce the repetition of the when blocks)
|
/ok-to-test |
Apologies for the delay in updating this PR, and the suggestions for how to improve this. Would something like this be acceptable?
This would cause it to fail only if the certificate is eg unable to be parsed for whatever reason. |
68f4082
to
9d2bc14
Compare
9d2bc14
to
da80d1f
Compare
Yes, I think that should work. (Regarding the block rescue stuff, thinking about it a second time I'm not sure it would work, given how |
/approve |
1aa46a5
to
f165ac4
Compare
I have rebased this now :) |
/lgtm
/approve
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: mhamzahkhan, VannTen The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
What type of PR is this?
What this PR does / why we need it:
Newer versions of OpenSSL appear to return an exit code of 1 if the checkhost doesn't match. Older versions of OpenSSL seem to return a 0 regardless of if it matched or not:
This causes ansible to exit on the SAN check:
Adding
ignore_errors: true
should fix thisWhich issue(s) this PR fixes:
Fixes #
Special notes for your reviewer:
Does this PR introduce a user-facing change?: