Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[release-1.20] kubernetes.default.svc not among SANs in Kubernetes API serving certificate #1113

Closed
fapatel1 opened this issue Jun 8, 2021 · 1 comment
Assignees
Labels
kind/bug Something isn't working

Comments

@fapatel1
Copy link

fapatel1 commented Jun 8, 2021

Pull through "kubernetes.default.svc not among SANs in Kubernetes API serving certificate" from k3s-io/k3s#3392 to release-1.21 branch

@fapatel1 fapatel1 added the kind/bug Something isn't working label Jun 8, 2021
@fapatel1 fapatel1 added this to the v1.20.8+rke2r1 milestone Jun 8, 2021
@fapatel1 fapatel1 changed the title [release-1.21] kubernetes.default.svc not among SANs in Kubernetes API serving certificate [release-1.20] kubernetes.default.svc not among SANs in Kubernetes API serving certificate Jun 8, 2021
brandond added a commit to brandond/rke2 that referenced this issue Jun 9, 2021
Signed-off-by: Brad Davidson <brad.davidson@rancher.com>
@brandond brandond added this to To Triage in Development [DEPRECATED] via automation Jun 9, 2021
@brandond brandond moved this from To Triage to Peer Review in Development [DEPRECATED] Jun 9, 2021
brandond added a commit that referenced this issue Jun 11, 2021
Signed-off-by: Brad Davidson <brad.davidson@rancher.com>
@brandond brandond moved this from Peer Review to To Test in Development [DEPRECATED] Jun 11, 2021
@ShylajaDevadiga
Copy link
Contributor

Validated fix using v1.20.8-rc1+rke2r1
On new install

$ echo QUIT | openssl s_client -connect localhost:6443 2>/dev/null | openssl x509 -noout -text |grep DNS
                DNS:localhost, DNS:kubernetes, DNS:kubernetes.default, DNS:kubernetes.default.svc, DNS:kubernetes.default.svc.cluster.local, IP Address:10.43.0.1, IP Address:127.0.0.1, IP Address:172.31.5.149, IP Address:10.43.0.1

root@nginx-deployment-66b6c48dd5-jk9bv:/# curl --cacert /run/secrets/kubernetes.io/serviceaccount/ca.crt https://kubernetes.default.svc
{
  "kind": "Status",
  "apiVersion": "v1",
  "metadata": {
    
  },
  "status": "Failure",
  "message": "Unauthorized",
  "reason": "Unauthorized",
  "code": 401
}

On upgrade from v1.20.7+rke2r2 to v1.20.8-rc1+rke2r1
Before upgrade

ubuntu@ip-172-31-5-149:~$ echo QUIT | openssl s_client -connect localhost:6443 2>/dev/null | openssl x509 -noout -text |grep DNS
                DNS:localhost, DNS:kubernetes, DNS:kubernetes.default, DNS:kubernetes.default.svc.cluster.local, IP Address:10.43.0.1, IP Address:127.0.0.1, IP Address:172.31.5.149, IP Address:10.43.0.1

After upgrade

ubuntu@ip-172-31-5-149:~$ echo QUIT | openssl s_client -connect localhost:6443 2>/dev/null | openssl x509 -noout -text |grep DNS
                DNS:localhost, DNS:kubernetes, DNS:kubernetes.default, DNS:kubernetes.default.svc, DNS:kubernetes.default.svc.cluster.local, IP Address:10.43.0.1, IP Address:127.0.0.1, IP Address:172.31.5.149, IP Address:10.43.0.1

Development [DEPRECATED] automation moved this from To Test to Done Issue / Merged PR Jun 22, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/bug Something isn't working
Projects
No open projects
Development [DEPRECATED]
Done Issue / Merged PR
Development

No branches or pull requests

3 participants