)]}'
{"ansible/group_vars/all.yml":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"22872883d9a0937b81fdc619153a534fa7b5ca8c","unresolved":false,"context_lines":[{"line_number":752,"context_line":"kolla_enable_tls_external: \"{{ kolla_enable_tls_internal if kolla_same_external_internal_vip | bool else \u0027no\u0027 }}\""},{"line_number":753,"context_line":"kolla_external_fqdn_cert: \"{{ node_config }}/certificates/haproxy.pem\""},{"line_number":754,"context_line":"kolla_internal_fqdn_cert: \"{{ node_config }}/certificates/haproxy-internal.pem\""},{"line_number":755,"context_line":"kolla_external_fqdn_cacert: \"{{ node_config }}/certificates/ca/haproxy.crt\""},{"line_number":756,"context_line":"kolla_internal_fqdn_cacert: \"{{ node_config }}/certificates/ca/haproxy-internal.crt\""},{"line_number":757,"context_line":"kolla_copy_ca_into_containers: \"no\""},{"line_number":758,"context_line":"kolla_verify_internal_ca_certs: \"yes\""}],"source_content_type":"text/x-yaml","patch_set":1,"id":"3fa7e38b_67103659","line":755,"range":{"start_line":755,"start_character":60,"end_line":755,"end_character":63},"updated":"2020-01-10 15:41:55.000000000","message":"If we\u0027re going to change the CA path we need to be clear in release notes. We might want a distinction between the CA file we configure in admin-openrc.sh vs. the location of CA files to put into containers. I suppose this this simpler, but will require existing users to change their config layout.","commit_id":"c06195265fd3b7735a75ee1579e71ff923c233ca"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"22872883d9a0937b81fdc619153a534fa7b5ca8c","unresolved":false,"context_lines":[{"line_number":753,"context_line":"kolla_external_fqdn_cert: \"{{ node_config }}/certificates/haproxy.pem\""},{"line_number":754,"context_line":"kolla_internal_fqdn_cert: \"{{ node_config }}/certificates/haproxy-internal.pem\""},{"line_number":755,"context_line":"kolla_external_fqdn_cacert: \"{{ node_config }}/certificates/ca/haproxy.crt\""},{"line_number":756,"context_line":"kolla_internal_fqdn_cacert: \"{{ node_config }}/certificates/ca/haproxy-internal.crt\""},{"line_number":757,"context_line":"kolla_copy_ca_into_containers: \"no\""},{"line_number":758,"context_line":"kolla_verify_internal_ca_certs: \"yes\""},{"line_number":759,"context_line":""}],"source_content_type":"text/x-yaml","patch_set":1,"id":"3fa7e38b_c7000a06","line":756,"updated":"2020-01-10 15:41:55.000000000","message":"If changing these, please update etc/kolla/globals.yml to match.","commit_id":"c06195265fd3b7735a75ee1579e71ff923c233ca"}],"ansible/roles/certificates/templates/openssl-kolla.cnf.j2":[{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"7b66896847b8707e361182c38859fb9df64ffb2f","unresolved":false,"context_lines":[{"line_number":1,"context_line":"[req]"},{"line_number":2,"context_line":"prompt \u003d no"},{"line_number":3,"context_line":"distinguished_name \u003d req_distinguished_name"},{"line_number":4,"context_line":"req_extensions \u003d v3_req"},{"line_number":5,"context_line":""}],"source_content_type":"text/x-jinja2","patch_set":14,"id":"3fa7e38b_d82d4f90","line":2,"updated":"2020-01-29 08:08:42.000000000","message":"is this a part of some fix?","commit_id":"d100904f2c42dea3338e5016c46014ee3132807c"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"c728116477f6da1ebfde7ace148b05d6e6b4f967","unresolved":false,"context_lines":[{"line_number":1,"context_line":"[req]"},{"line_number":2,"context_line":"prompt \u003d no"},{"line_number":3,"context_line":"distinguished_name \u003d req_distinguished_name"},{"line_number":4,"context_line":"req_extensions \u003d v3_req"},{"line_number":5,"context_line":""}],"source_content_type":"text/x-jinja2","patch_set":14,"id":"3fa7e38b_e44adaac","line":2,"in_reply_to":"3fa7e38b_12809b9b","updated":"2020-01-29 23:13:27.000000000","message":"Validated it is not a required fix - our generate step will pass even if \"prompt \u003d yes\", but is semantically correct. Does not require a backport.","commit_id":"d100904f2c42dea3338e5016c46014ee3132807c"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"9733b7fe3250ac13724d1af847317852afaebfd2","unresolved":false,"context_lines":[{"line_number":1,"context_line":"[req]"},{"line_number":2,"context_line":"prompt \u003d no"},{"line_number":3,"context_line":"distinguished_name \u003d req_distinguished_name"},{"line_number":4,"context_line":"req_extensions \u003d v3_req"},{"line_number":5,"context_line":""}],"source_content_type":"text/x-jinja2","patch_set":14,"id":"3fa7e38b_12809b9b","line":2,"in_reply_to":"3fa7e38b_72ec6f91","updated":"2020-01-29 17:27:23.000000000","message":"Then extract and backport I think. :-)","commit_id":"d100904f2c42dea3338e5016c46014ee3132807c"},{"author":{"_account_id":30810,"name":"James Kirsch","email":"generalfuzz@gmail.com","username":"generalfuzz"},"change_message_id":"5a0f69b5047d4a40aba8af6a48c953735c901e7e","unresolved":false,"context_lines":[{"line_number":1,"context_line":"[req]"},{"line_number":2,"context_line":"prompt \u003d no"},{"line_number":3,"context_line":"distinguished_name \u003d req_distinguished_name"},{"line_number":4,"context_line":"req_extensions \u003d v3_req"},{"line_number":5,"context_line":""}],"source_content_type":"text/x-jinja2","patch_set":14,"id":"3fa7e38b_72ec6f91","line":2,"in_reply_to":"3fa7e38b_d82d4f90","updated":"2020-01-29 17:23:50.000000000","message":"yes","commit_id":"d100904f2c42dea3338e5016c46014ee3132807c"},{"author":{"_account_id":30491,"name":"Radosław Piliszek","display_name":"Radek","email":"radek@piliszek.it","username":"yoctozepto","status":"self-employed techologist, collaborating mostly with 7bulls.com"},"change_message_id":"da514939c416ebe0305c5603969f750c6afab28c","unresolved":false,"context_lines":[{"line_number":1,"context_line":"[req]"},{"line_number":2,"context_line":"prompt \u003d no"},{"line_number":3,"context_line":"distinguished_name \u003d req_distinguished_name"},{"line_number":4,"context_line":"req_extensions \u003d v3_req"},{"line_number":5,"context_line":""}],"source_content_type":"text/x-jinja2","patch_set":14,"id":"3fa7e38b_58586dfb","line":2,"in_reply_to":"3fa7e38b_e44adaac","updated":"2020-01-30 07:54:41.000000000","message":"Thank you! Then we are fine with this.","commit_id":"d100904f2c42dea3338e5016c46014ee3132807c"}],"releasenotes/notes/generate-internal-external-self-signed-certs-c631a9d934d31fac.yaml":[{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"dd09d11c84eb3781b789e67b30de4637f54d703d","unresolved":false,"context_lines":[{"line_number":6,"context_line":"    files will be the same."},{"line_number":7,"context_line":"upgrade:"},{"line_number":8,"context_line":"  - |"},{"line_number":9,"context_line":"    The path for the certificate authority certificate has been moved"},{"line_number":10,"context_line":"    from:"},{"line_number":11,"context_line":"    \"{{ node_config }}/certificates/haproxy-ca.crt\""},{"line_number":12,"context_line":"    to:"},{"line_number":13,"context_line":"    \"{{ node_config }}/certificates/ca/haproxy.crt\""},{"line_number":14,"context_line":""},{"line_number":15,"context_line":"    Kolla-Ansible now expects all CA certificates to be in the"},{"line_number":16,"context_line":"    \"{{ node_config }}/certificates/ca/\" path."}],"source_content_type":"text/x-yaml","patch_set":5,"id":"3fa7e38b_e374de39","line":16,"range":{"start_line":9,"start_character":0,"end_line":16,"end_character":46},"updated":"2020-01-15 10:08:36.000000000","message":"The default values for ``kolla_external_fqdn_cacert`` and ``kolla_internal_fqdn_cacert`` have been changed from ... to .... These variables set the value for the ``OS_CACERT`` environment variable in ``admin-openrc.sh``. This has been done to allow these certificates to be copied into containers when ``kolla_copy_ca_into_containers`` is true.","commit_id":"4679e40a76590d2fbb4d42a9a78cb53593c53108"},{"author":{"_account_id":14826,"name":"Mark Goddard","email":"markgoddard86@gmail.com","username":"mgoddard"},"change_message_id":"69d78dbeaf2a736008c601f7a4e982cf537fc12a","unresolved":false,"context_lines":[{"line_number":16,"context_line":"    from:"},{"line_number":17,"context_line":"    \"{{ node_config }}/certificates/haproxy-ca-internal.crt\""},{"line_number":18,"context_line":"    to:"},{"line_number":19,"context_line":"    \"{{ node_config }}/certificates/ca/haproxy-innteral.crt\""},{"line_number":20,"context_line":""},{"line_number":21,"context_line":"    These variables set the value for the ``OS_CACERT`` environment variable in"},{"line_number":22,"context_line":"    ``admin-openrc.sh``. This has been done to allow these certificates to be"}],"source_content_type":"text/x-yaml","patch_set":9,"id":"3fa7e38b_4860d40d","line":19,"range":{"start_line":19,"start_character":47,"end_line":19,"end_character":55},"updated":"2020-01-27 12:18:35.000000000","message":"spelling","commit_id":"bd8236ba4db749b713178fc10797b53360404773"}]}
