OpenShift 4 で、不明な認証局によって署名された x509 証明書による RouterCertsDegraded 警告
Issue
-
デフォルトの Ingress 証明書をカスタム証明書に置き換えた後、
authenticationクラスター Operator が以下のエラーを表示してデグレード状態になりました。RouterCertsDegraded: secret/v4-0-config-system-router-certs.spec.data[apps.example.com] -n openshift-authentication: certificate could not validate route hostname oauth-openshift.apps.example.com: x509: certificate signed by unknown authorityEvent(v1.ObjectReference{Kind:"Deployment", Namespace:"openshift-authentication-operator", Name:"authentication-operator", UID:"<UID>", APIVersion:"apps/v1", ResourceVersion:"", FieldPath:""}): type: 'Normal' reason: 'OperatorStatusChanged' Status for clusteroperator/authentication changed: Degraded changed from False to True ("RouterCertsDegraded: secret/v4-0-config-system-router-certs.spec.data[apps.example.com] -n openshift-authentication: certificate could not validate route hostname oauth-openshift.apps.example.com: x509: certificate signed by unknown authority") [...]
Environment
- Red Hat OpenShift Container Platform (RHOCP)
- 4
- Ingress カスタム証明書
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.