)]}'
{"defaults/main.yml":[{"author":{"_account_id":31749,"name":"James Gibson","email":"james.gibson@bbc.co.uk","username":"jamesgibo"},"change_message_id":"c8376fdb4084cecd4230d269d8340f15401ab942","unresolved":true,"context_lines":[{"line_number":245,"context_line":"    owner: \"mysql\""},{"line_number":246,"context_line":"    group: \"root\""},{"line_number":247,"context_line":"    mode: \"0600\""},{"line_number":248,"context_line":"  - src: \"{{ galera_user_ssl_ca_cert | default(galera_pki_intermediate_cert_path) }}\""},{"line_number":249,"context_line":"    dest: \"{{ galera_ssl_ca_cert }}\""},{"line_number":250,"context_line":"    owner: \"root\""},{"line_number":251,"context_line":"    group: \"root\""}],"source_content_type":"text/x-yaml","patch_set":2,"id":"ba857f02_e8fea86c","side":"PARENT","line":248,"updated":"2021-12-08 08:53:53.000000000","message":"Would it be better to use the Root CA here instead of the intermediate chain?\nIf the server certificate includes the intermediate when sent there should be no need for the intermediate to be stored on the client.\nIf Galera supports this, libvirt for example ignored any certificate chains in the server certificate for example.","commit_id":"19d60b21f8072772cf776ca4d2257581c14ad305"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"ac88c7719c64d42bfbbc34b7e1922609e5604933","unresolved":true,"context_lines":[{"line_number":245,"context_line":"    owner: \"mysql\""},{"line_number":246,"context_line":"    group: \"root\""},{"line_number":247,"context_line":"    mode: \"0600\""},{"line_number":248,"context_line":"  - src: \"{{ galera_user_ssl_ca_cert | default(galera_pki_intermediate_cert_path) }}\""},{"line_number":249,"context_line":"    dest: \"{{ galera_ssl_ca_cert }}\""},{"line_number":250,"context_line":"    owner: \"root\""},{"line_number":251,"context_line":"    group: \"root\""}],"source_content_type":"text/x-yaml","patch_set":2,"id":"dad21847_60856525","side":"PARENT","line":248,"in_reply_to":"ba857f02_e8fea86c","updated":"2021-12-08 09:58:20.000000000","message":"well, yes, that would probably be better. We would need to change variable names though and edit release note...","commit_id":"19d60b21f8072772cf776ca4d2257581c14ad305"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"96f2f4a471c46ac81b721e804c84fb0c29e58919","unresolved":true,"context_lines":[{"line_number":245,"context_line":"    owner: \"mysql\""},{"line_number":246,"context_line":"    group: \"root\""},{"line_number":247,"context_line":"    mode: \"0600\""},{"line_number":248,"context_line":"  - src: \"{{ galera_user_ssl_ca_cert | default(galera_pki_intermediate_cert_path) }}\""},{"line_number":249,"context_line":"    dest: \"{{ galera_ssl_ca_cert }}\""},{"line_number":250,"context_line":"    owner: \"root\""},{"line_number":251,"context_line":"    group: \"root\""}],"source_content_type":"text/x-yaml","patch_set":2,"id":"916ad4ad_e7f0ff4c","side":"PARENT","line":248,"in_reply_to":"dad21847_60856525","updated":"2021-12-08 10:12:33.000000000","message":"But to be fair - mysqlclient is equally happy with root as with intermediate chain.","commit_id":"19d60b21f8072772cf776ca4d2257581c14ad305"}]}
