Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[DPE-1626] Add support for certificates and CA renewal #94

Draft
wants to merge 13 commits into
base: main
Choose a base branch
from

Conversation

Mehdi-Bendriss
Copy link
Contributor

@Mehdi-Bendriss Mehdi-Bendriss commented Jun 7, 2023

Issue

This PR implements DPE-1626, namely this PR implements:

  • Replace the certificates / keys formats to using pkcs12 trustores / keystores
  • Allow replacement of CA and regeneration of certificates on all nodes
  • Fix bug when TLS relation removed and reestablished

Notes:

This PR is pending more info on the following raised issue upstream, background being that it seems we can only have the changes reflected after a full cluster restart which is not expected nor ideal. ElasticSearch supports the rolling restart in such a scenario

@phvalguima
Copy link
Contributor

@Mehdi-Bendriss: there was quite some work on this topic from @reneradoi. Do we still need to keep this PR or are we okay to close it?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants