OpenShift Update Service is not getting registry certificates in OpenShift 4

Solution Verified - Updated -

Issue

  • The graph-builder container in the service pods contains errors like the following ones with message unable to get local issuer certificate, unable to get issuer certificate or self signed certificate:

    ERROR graph_builder::graph] failed to fetch all release metadata from <test-registry>:8443/<image>
    ERROR graph_builder::graph] http transport error: error sending request for url (<test-registry>:8443/v2/): error trying to connect: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:ssl/statem/statem_clnt.c:1915: (unable to get issuer certificate)
    ERROR graph_builder::graph] error sending request for url (<test-registry>:8443/v2/): error trying to connect: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:ssl/statem/statem_clnt.c:1915: (unable to get issuer certificate)
    ERROR graph_builder::graph] error trying to connect: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:ssl/statem/statem_clnt.c:1915: (unable to get issuer certificate)
    ERROR graph_builder::graph] error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:ssl/statem/statem_clnt.c:1915: (unable to get issuer certificate)
    
    DEBUG cincinnati::plugins::internal::graph_builder::commons] unable to process certificate ca-bundle.trust.crt: builder error: error:0909006C:PEM routines:get_name:no start line:crypto/pem/pem_lib.c:745:Expecting: CERTIFICATE
    ERROR graph_builder::graph] failed to fetch all release metadata from <test-registry>:8443/<image>
    ERROR graph_builder::graph] http transport error: error sending request for url (<test-registry>:8443/v2/): error trying to connect: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:ssl/statem/statem_clnt.c:1915: (self signed certificate in certificate chain)
    

Environment

  • Red Hat OpenShift Container Platform (RHOCP)
    • 4
  • OpenShift Update Service (OSUS)
    • 5.0
  • Secured registry

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content