LDAP authentication fails due to untrusted SSL certificate in Containerized Ansible Automation Platform environment
Environment
- Red Hat Ansible Automation Platform 2.5 , 2.6 , 27
- Red Hat Ansible Automation Platform Containerized environment
Issue
Error: SSL certificate verification fails due to untrusted CA on LDAP connection.
Resolution
1) Add the LDAP CA file to directory /home/[USER]/aap/tls/extracted
2) Correct the CA file SELinux label :
# chcon system_u:object_r:container_file_t:s0 /home/[USER]/aap/tls/extracted/[CA cert file]
3) Restart gateway container :
# systemctl --user restart automation-gateway
4) Validate the file in the container :
$ podman exec -it automation-gateway ls -l /etc/pki/ca-trust/extracted
5) On the LDAP authentication method , add the following under "LDAP Connection Options":
OPT_X_TLS_CACERTFILE: /etc/pki/ca-trust/extracted/[CA cert file]
6) Try to use the TLS connection to the LDAP
7) Another alternative is to add the custom CA cert in the inventory and run the installer :
[all:vars]
custom_ca_cert=[Path to CA cert]
Root Cause
- Ansible Automation Platform is using self-signed SSL certificates generated by the installer while the used LDAP has its own custom SSL certificates.
- The CA of the LDAP SSL cert is not added to Ansible Automation Platform.
This solution is part of Red Hat’s fast-track publication program, providing a huge library of solutions that Red Hat engineers have created while supporting our customers. To give you the knowledge you need the instant it becomes available, these articles may be presented in a raw and unedited form.
Comments