HDDS-9420. [Compatibility]Enabling GRPC encryption causes SCM startup failure#5561
Merged
adoroszlai merged 2 commits intoapache:masterfrom Nov 10, 2023
Merged
HDDS-9420. [Compatibility]Enabling GRPC encryption causes SCM startup failure#5561adoroszlai merged 2 commits intoapache:masterfrom
adoroszlai merged 2 commits intoapache:masterfrom
Conversation
Contributor
Author
|
@fapifta , getTrustChain is used for SCM, OM and DN. For OM and DN, even root certificate is not considered, sub ca certificate still need be included in the TrustChain. So the mentioned removing the root certificate in certificate bundle solution is not tried here. It can be a different new improvement to the feature. |
adoroszlai
approved these changes
Nov 10, 2023
Contributor
adoroszlai
left a comment
There was a problem hiding this comment.
Thanks @ChenSammi for the fix. I have verified it using secure upgrade acceptance test locally (HDDS-5506, in-progress).
Contributor
Author
|
Thank you, @adoroszlai . |
ibrusentsev
pushed a commit
to ibrusentsev/ozone
that referenced
this pull request
Nov 14, 2023
jojochuang
pushed a commit
to jojochuang/ozone
that referenced
this pull request
Feb 1, 2024
…s SCM startup failure (apache#5561) (cherry picked from commit db55221) Change-Id: Ic8b4fb2c83a8efa75da04a49ef9c43f89abce388
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes were proposed in this pull request?
Resolve the backward compatibility issue introduced in HDDS-8588.
The root cause is that the listCA() call during SCM, will try to call SCM's SCMSecurityProtocolServer API, but this SCMSecurityProtocolServer is not ready at that time. The call has a max retry policy. So SCM will stuck in the retry and cannot startup.
The fix avoids the remote API call, use local on disk info to build the TrustChain.
What is the link to the Apache JIRA
https://issues.apache.org/jira/browse/HDDS-9420
How was this patch tested?
Tested it manually. Here is the step