OpenShift Router - CA Bundle Certificate Matching

Solution Verified - Updated -

Issue

When deploying Client authentication, a CA bundle is configured with multiple client certificates.

Generated Client Certs have CN and SAN List entries which are duplicates.
However, when clients connect it appears only the first matching certificate is checked and not all.
This means that only the first key and certificate in the bundle file can be used to authenticate.

Environment

OpenShift Container Platform
- 3.4
- 3.5
- 3.6
- 3.7
- 3.9

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content