]> git.apps.os.sepia.ceph.com Git - ceph.git/commitdiff
mgr/cephadm: reverting usage of Org Name 'Ceph' in self-signed certs
authorRedouane Kachach <rkachach@ibm.com>
Tue, 18 Feb 2025 12:42:17 +0000 (13:42 +0100)
committerRedouane Kachach <rkachach@ibm.com>
Tue, 11 Mar 2025 09:34:23 +0000 (10:34 +0100)
This could cause issues on upgrades as it imply chaning the root CA CN

Signed-off-by: Redouane Kachach <rkachach@ibm.com>
src/pybind/mgr/cephadm/ssl_cert_utils.py

index d641838c5dcdeb8a43bde5b4a762baf1abb24272..ee8d88e55f031579ffc68527f5390f2e051feb09 100644 (file)
@@ -137,7 +137,6 @@ class SSLCerts:
         root_public_key = self.root_key.public_key()
         root_builder = x509.CertificateBuilder()
         root_ca_name = x509.Name([
-            x509.NameAttribute(NameOID.ORGANIZATION_NAME, u"Ceph"),
             x509.NameAttribute(NameOID.COMMON_NAME, u'cephadm-root'),
         ])
         root_builder = root_builder.subject_name(root_ca_name)
@@ -199,7 +198,6 @@ class SSLCerts:
 
         builder = x509.CertificateBuilder()
         root_ca_name = x509.Name([
-            x509.NameAttribute(NameOID.ORGANIZATION_NAME, u"Ceph"),
             x509.NameAttribute(NameOID.COMMON_NAME, u'cephadm-root'),
         ])
         builder = builder.subject_name(x509.Name([x509.NameAttribute(NameOID.COMMON_NAME, addrs[0]), ]))