)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":31646,"name":"Carmen Rata","email":"carmen.rata@windriver.com","username":"crata"},"change_message_id":"7b987eb2e67c805340f4f6bd884968b88096432a","unresolved":true,"context_lines":[{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Also with this change, secure openldap certificate generation and"},{"line_number":19,"context_line":"configuration now is done during unlock instead of being triggered"},{"line_number":20,"context_line":"by cert-mon at runtime after controller-0 is unlocked, because"},{"line_number":21,"context_line":"cert-mon could trigger certificate generation and configuration"},{"line_number":22,"context_line":"before controller-1 is installed, causing openldap certificate never"},{"line_number":23,"context_line":"generated and configured on controller-1."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"f9410b03_2e239a66","line":20,"updated":"2022-08-23 21:32:31.000000000","message":"This explanation is confusing. Secure openldap configuration was always done during unlock. This is because certMon was started during unlock.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"c24859b80bcb2e0ab903896549474e8317b4a33f","unresolved":false,"context_lines":[{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Also with this change, secure openldap certificate generation and"},{"line_number":19,"context_line":"configuration now is done during unlock instead of being triggered"},{"line_number":20,"context_line":"by cert-mon at runtime after controller-0 is unlocked, because"},{"line_number":21,"context_line":"cert-mon could trigger certificate generation and configuration"},{"line_number":22,"context_line":"before controller-1 is installed, causing openldap certificate never"},{"line_number":23,"context_line":"generated and configured on controller-1."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"61bfe464_cc90706d","line":20,"in_reply_to":"8f2702bf_dfa036c2","updated":"2022-08-26 13:38:33.000000000","message":"Done","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"26a0317494f72025cfe28492153bd965a333b4c8","unresolved":true,"context_lines":[{"line_number":17,"context_line":""},{"line_number":18,"context_line":"Also with this change, secure openldap certificate generation and"},{"line_number":19,"context_line":"configuration now is done during unlock instead of being triggered"},{"line_number":20,"context_line":"by cert-mon at runtime after controller-0 is unlocked, because"},{"line_number":21,"context_line":"cert-mon could trigger certificate generation and configuration"},{"line_number":22,"context_line":"before controller-1 is installed, causing openldap certificate never"},{"line_number":23,"context_line":"generated and configured on controller-1."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"8f2702bf_dfa036c2","line":20,"in_reply_to":"f9410b03_2e239a66","updated":"2022-08-24 18:34:52.000000000","message":"Yes, secure openldap configuration is done during unlock, but currently openldap certificate is generated, and openldap is configured to use the certificate is done by cert-mon after unlock.\n\nBy certificate configuration I refer to:\n    -\u003e exec { \u0027ldap configuration update to enable TLS/SSL\u0027:\n      command \u003d\u003e \"ldapmodify -D ${dn} -w \\\"${admin_pw}\\\" -xH ldap:/// -f ${slapd_etc_path}/certs.ldif\",\n    }\n\nWith this change, the openldap certificate is generated, and openldap is configured to use the certificate are all done during unlock.\n\nI can reword this part of the commit message.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":31646,"name":"Carmen Rata","email":"carmen.rata@windriver.com","username":"crata"},"change_message_id":"7b987eb2e67c805340f4f6bd884968b88096432a","unresolved":true,"context_lines":[{"line_number":27,"context_line":"Test Plan on Debian (SX and DX):"},{"line_number":28,"context_line":"PASS: Package build, image build."},{"line_number":29,"context_line":"PASS: System deployment."},{"line_number":30,"context_line":"PASS: Openldap certificate and key files are generated, and slapd is"},{"line_number":31,"context_line":"      configured to use the certificate and key after controller is"},{"line_number":32,"context_line":"      unlocked."},{"line_number":33,"context_line":"PASS: sssd is connected to slapd on the secure port after unlock."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"e6827912_c45cb385","line":30,"range":{"start_line":30,"start_character":60,"end_line":30,"end_character":66},"updated":"2022-08-23 21:32:31.000000000","message":"I think is better to say openldap is configured to be secure, using the SSL/TLS certificate.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"c24859b80bcb2e0ab903896549474e8317b4a33f","unresolved":false,"context_lines":[{"line_number":27,"context_line":"Test Plan on Debian (SX and DX):"},{"line_number":28,"context_line":"PASS: Package build, image build."},{"line_number":29,"context_line":"PASS: System deployment."},{"line_number":30,"context_line":"PASS: Openldap certificate and key files are generated, and slapd is"},{"line_number":31,"context_line":"      configured to use the certificate and key after controller is"},{"line_number":32,"context_line":"      unlocked."},{"line_number":33,"context_line":"PASS: sssd is connected to slapd on the secure port after unlock."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"99abb997_54cca187","line":30,"range":{"start_line":30,"start_character":60,"end_line":30,"end_character":66},"in_reply_to":"6e0888bf_6a7dce72","updated":"2022-08-26 13:38:33.000000000","message":"Done","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"26a0317494f72025cfe28492153bd965a333b4c8","unresolved":true,"context_lines":[{"line_number":27,"context_line":"Test Plan on Debian (SX and DX):"},{"line_number":28,"context_line":"PASS: Package build, image build."},{"line_number":29,"context_line":"PASS: System deployment."},{"line_number":30,"context_line":"PASS: Openldap certificate and key files are generated, and slapd is"},{"line_number":31,"context_line":"      configured to use the certificate and key after controller is"},{"line_number":32,"context_line":"      unlocked."},{"line_number":33,"context_line":"PASS: sssd is connected to slapd on the secure port after unlock."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"6e0888bf_6a7dce72","line":30,"range":{"start_line":30,"start_character":60,"end_line":30,"end_character":66},"in_reply_to":"e6827912_c45cb385","updated":"2022-08-24 18:34:52.000000000","message":"Sure","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":31646,"name":"Carmen Rata","email":"carmen.rata@windriver.com","username":"crata"},"change_message_id":"7b987eb2e67c805340f4f6bd884968b88096432a","unresolved":true,"context_lines":[{"line_number":30,"context_line":"PASS: Openldap certificate and key files are generated, and slapd is"},{"line_number":31,"context_line":"      configured to use the certificate and key after controller is"},{"line_number":32,"context_line":"      unlocked."},{"line_number":33,"context_line":"PASS: sssd is connected to slapd on the secure port after unlock."},{"line_number":34,"context_line":"PASS: ldap functions work properly (ldap user creation, user login"},{"line_number":35,"context_line":"      on console and by ssh etc)."},{"line_number":36,"context_line":"PASS: For DX system, ldap functions still work properly after swact."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"b702df99_c7b69c48","line":33,"updated":"2022-08-23 21:32:31.000000000","message":"How did you test sssd is connected?","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"c24859b80bcb2e0ab903896549474e8317b4a33f","unresolved":false,"context_lines":[{"line_number":30,"context_line":"PASS: Openldap certificate and key files are generated, and slapd is"},{"line_number":31,"context_line":"      configured to use the certificate and key after controller is"},{"line_number":32,"context_line":"      unlocked."},{"line_number":33,"context_line":"PASS: sssd is connected to slapd on the secure port after unlock."},{"line_number":34,"context_line":"PASS: ldap functions work properly (ldap user creation, user login"},{"line_number":35,"context_line":"      on console and by ssh etc)."},{"line_number":36,"context_line":"PASS: For DX system, ldap functions still work properly after swact."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"a7edb583_92f07eac","line":33,"in_reply_to":"6f37ad1c_3545e36a","updated":"2022-08-26 13:38:33.000000000","message":"Done","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"26a0317494f72025cfe28492153bd965a333b4c8","unresolved":true,"context_lines":[{"line_number":30,"context_line":"PASS: Openldap certificate and key files are generated, and slapd is"},{"line_number":31,"context_line":"      configured to use the certificate and key after controller is"},{"line_number":32,"context_line":"      unlocked."},{"line_number":33,"context_line":"PASS: sssd is connected to slapd on the secure port after unlock."},{"line_number":34,"context_line":"PASS: ldap functions work properly (ldap user creation, user login"},{"line_number":35,"context_line":"      on console and by ssh etc)."},{"line_number":36,"context_line":"PASS: For DX system, ldap functions still work properly after swact."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"6f37ad1c_3545e36a","line":33,"in_reply_to":"b702df99_c7b69c48","updated":"2022-08-24 18:34:52.000000000","message":"I tested by:\n- getent passwd\n- id admin, id operator\n- console login by ldap user\n- remote ssh login by ldap user\n- check sssd log that the domain is connected.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":31646,"name":"Carmen Rata","email":"carmen.rata@windriver.com","username":"crata"},"change_message_id":"7b987eb2e67c805340f4f6bd884968b88096432a","unresolved":true,"context_lines":[{"line_number":34,"context_line":"PASS: ldap functions work properly (ldap user creation, user login"},{"line_number":35,"context_line":"      on console and by ssh etc)."},{"line_number":36,"context_line":"PASS: For DX system, ldap functions still work properly after swact."},{"line_number":37,"context_line":""},{"line_number":38,"context_line":"Test Plan on CentOS:"},{"line_number":39,"context_line":"PASS: ldap functions work properly (ldap user creation, user login"},{"line_number":40,"context_line":"      on console and by ssh etc)"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"d9de52d6_6b7da957","line":37,"updated":"2022-08-23 21:32:31.000000000","message":"There should be test for sssd connection using openldap user ssh from remote server.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"c24859b80bcb2e0ab903896549474e8317b4a33f","unresolved":false,"context_lines":[{"line_number":34,"context_line":"PASS: ldap functions work properly (ldap user creation, user login"},{"line_number":35,"context_line":"      on console and by ssh etc)."},{"line_number":36,"context_line":"PASS: For DX system, ldap functions still work properly after swact."},{"line_number":37,"context_line":""},{"line_number":38,"context_line":"Test Plan on CentOS:"},{"line_number":39,"context_line":"PASS: ldap functions work properly (ldap user creation, user login"},{"line_number":40,"context_line":"      on console and by ssh etc)"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"e0dedbd3_2383e208","line":37,"in_reply_to":"7101e015_99c79378","updated":"2022-08-26 13:38:33.000000000","message":"Done","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"26a0317494f72025cfe28492153bd965a333b4c8","unresolved":true,"context_lines":[{"line_number":34,"context_line":"PASS: ldap functions work properly (ldap user creation, user login"},{"line_number":35,"context_line":"      on console and by ssh etc)."},{"line_number":36,"context_line":"PASS: For DX system, ldap functions still work properly after swact."},{"line_number":37,"context_line":""},{"line_number":38,"context_line":"Test Plan on CentOS:"},{"line_number":39,"context_line":"PASS: ldap functions work properly (ldap user creation, user login"},{"line_number":40,"context_line":"      on console and by ssh etc)"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"7101e015_99c79378","line":37,"in_reply_to":"d9de52d6_6b7da957","updated":"2022-08-24 18:34:52.000000000","message":"PASS: ldap functions work properly (ldap user creation, user login\n      on console and by ssh etc).\n      \nThe \"user login by ssh\" in the above test case is openldap user ssh from remote server.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":32841,"name":"Reinildes Oliveira","display_name":"Rei Oliveira","email":"Reinildes.JoseMateusOliveira@windriver.com","username":"rjosemat"},"change_message_id":"bdc6a24fd37c8253ebeea1e66ef2843b2c944dfc","unresolved":true,"context_lines":[{"line_number":41,"context_line":""},{"line_number":42,"context_line":"Story: 2009834"},{"line_number":43,"context_line":"Task: 46067"},{"line_number":44,"context_line":"Depends-On: https://review.opendev.org/c/starlingx/metal/+/854203"},{"line_number":45,"context_line":"Signed-off-by: Andy Ning \u003candy.ning@windriver.com\u003e"},{"line_number":46,"context_line":"Change-Id: Ia3f1a284109e3f032464f239efcfec273eb2efe1"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"6aeee9ce_62912bbc","line":44,"range":{"start_line":44,"start_character":0,"end_line":44,"end_character":7},"updated":"2022-08-23 20:52:34.000000000","message":"Do you need a depends-on to config repository as well?","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":32841,"name":"Reinildes Oliveira","display_name":"Rei Oliveira","email":"Reinildes.JoseMateusOliveira@windriver.com","username":"rjosemat"},"change_message_id":"d22c6931e11946e966e11122e0136a016e714705","unresolved":false,"context_lines":[{"line_number":41,"context_line":""},{"line_number":42,"context_line":"Story: 2009834"},{"line_number":43,"context_line":"Task: 46067"},{"line_number":44,"context_line":"Depends-On: https://review.opendev.org/c/starlingx/metal/+/854203"},{"line_number":45,"context_line":"Signed-off-by: Andy Ning \u003candy.ning@windriver.com\u003e"},{"line_number":46,"context_line":"Change-Id: Ia3f1a284109e3f032464f239efcfec273eb2efe1"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"35558c82_1635d2ea","line":44,"range":{"start_line":44,"start_character":0,"end_line":44,"end_character":7},"in_reply_to":"3fba68da_4685419f","updated":"2022-08-25 22:15:07.000000000","message":"Ack","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"b38a1ddb188f5cd0a3e1e1e7ba0a85f296a0e01e","unresolved":true,"context_lines":[{"line_number":41,"context_line":""},{"line_number":42,"context_line":"Story: 2009834"},{"line_number":43,"context_line":"Task: 46067"},{"line_number":44,"context_line":"Depends-On: https://review.opendev.org/c/starlingx/metal/+/854203"},{"line_number":45,"context_line":"Signed-off-by: Andy Ning \u003candy.ning@windriver.com\u003e"},{"line_number":46,"context_line":"Change-Id: Ia3f1a284109e3f032464f239efcfec273eb2efe1"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"3fba68da_4685419f","line":44,"range":{"start_line":44,"start_character":0,"end_line":44,"end_character":7},"in_reply_to":"6aeee9ce_62912bbc","updated":"2022-08-23 21:12:26.000000000","message":"The dependencies are complicated among the 9 reviews. Instead, I WF-1 the pmon review, and all the other 8 reviews depends on it, making the pmon review as a \"gate\". Once all the 8 reviews get WF+1, I\u0027ll release pmon review. This way all the 9 reviews will be merged together. This is a technique I learnt from others.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":31646,"name":"Carmen Rata","email":"carmen.rata@windriver.com","username":"crata"},"change_message_id":"17c37cddceed137fd387d8060ea0ff4520a2ed1b","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"1f0b1fa1_4a3b9327","updated":"2022-08-25 20:29:49.000000000","message":"LGTM","commit_id":"3088ad6077393e8ea19ecd4e57185fd578eebb5b"},{"author":{"_account_id":28459,"name":"Bob Church","email":"robert.church@windriver.com","username":"rchurch"},"change_message_id":"4f1131c9b587656d091cd0f10fc406cd416f3549","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":4,"id":"760aa491_3bbdb17a","updated":"2022-08-26 19:10:45.000000000","message":"recheck","commit_id":"3088ad6077393e8ea19ecd4e57185fd578eebb5b"}],"puppet-manifests/src/manifests/controller.pp":[{"author":{"_account_id":9926,"name":"John Kung","email":"john.kung@windriver.com","username":"jkung"},"change_message_id":"e7beaa184041befc08203430b393643b94daa2f3","unresolved":false,"context_lines":[{"line_number":36,"context_line":"include ::platform::password"},{"line_number":37,"context_line":"include ::platform::ldap::server"},{"line_number":38,"context_line":"include ::platform::ldap::client"},{"line_number":39,"context_line":"include ::platform::sssd"},{"line_number":40,"context_line":"include ::platform::ntp::server"},{"line_number":41,"context_line":"include ::platform::ptpinstance"},{"line_number":42,"context_line":"include ::platform::ptpinstance::nic_clock"}],"source_content_type":"text/x-puppet","patch_set":3,"id":"b2b0c5d9_81346dd5","line":39,"updated":"2022-08-24 21:14:43.000000000","message":"ok, this is already in aio.pp","commit_id":"a5799ce75779ea48e46367419b91b4425a4d032d"}],"puppet-manifests/src/modules/platform/manifests/ldap.pp":[{"author":{"_account_id":31646,"name":"Carmen Rata","email":"carmen.rata@windriver.com","username":"crata"},"change_message_id":"7b987eb2e67c805340f4f6bd884968b88096432a","unresolved":true,"context_lines":[{"line_number":120,"context_line":"    }"},{"line_number":121,"context_line":"    -\u003e class { \u0027::platform::ldap::secure::config\u0027:}"},{"line_number":122,"context_line":"  }"},{"line_number":123,"context_line":"}"},{"line_number":124,"context_line":""},{"line_number":125,"context_line":""},{"line_number":126,"context_line":"class platform::ldap::client"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"b2a9e93f_083ea514","line":123,"updated":"2022-08-23 21:32:31.000000000","message":"This code can be refactored to remove duplication and be more readable. You basically remove 2 lines for Debian OS pertaining to nslcd and nscd.\nPlease explain why secure openldap config is triggered here.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"26a0317494f72025cfe28492153bd965a333b4c8","unresolved":true,"context_lines":[{"line_number":120,"context_line":"    }"},{"line_number":121,"context_line":"    -\u003e class { \u0027::platform::ldap::secure::config\u0027:}"},{"line_number":122,"context_line":"  }"},{"line_number":123,"context_line":"}"},{"line_number":124,"context_line":""},{"line_number":125,"context_line":""},{"line_number":126,"context_line":"class platform::ldap::client"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"db72c6cd_bab9f675","line":123,"in_reply_to":"b2a9e93f_083ea514","updated":"2022-08-24 18:34:52.000000000","message":"As you can see, what the \"platform::ldap::secure::config\" class does is:\n- create openldap-cert.crt and openldap-cert.key files\n- modify openldap configuration to use the certificate and key files by:\n (command \u003d\u003e \"ldapmodify -D ${dn} -w \\\"${admin_pw}\\\" -xH ldap:/// -f ${slapd_etc_path}/certs.ldif\")\n \nIn current implementation, the above is triggered by cert-mon after controller is unlocked. As described in the commit message, cert-mon could trigger the above operation before controller-1 is installed, causing openldap certificate never generated on controller-1.\n\nSince the unlock puppet manifest will be applied on both controllers, triggering the above operation during unlock will guarantee openldap certificate and key files are generated on controller-1.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":31646,"name":"Carmen Rata","email":"carmen.rata@windriver.com","username":"crata"},"change_message_id":"17c37cddceed137fd387d8060ea0ff4520a2ed1b","unresolved":false,"context_lines":[{"line_number":120,"context_line":"    }"},{"line_number":121,"context_line":"    -\u003e class { \u0027::platform::ldap::secure::config\u0027:}"},{"line_number":122,"context_line":"  }"},{"line_number":123,"context_line":"}"},{"line_number":124,"context_line":""},{"line_number":125,"context_line":""},{"line_number":126,"context_line":"class platform::ldap::client"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"4cf7c5bb_a38a179c","line":123,"in_reply_to":"db72c6cd_bab9f675","updated":"2022-08-25 20:29:49.000000000","message":"So the secure openldap configuration is done with the start of the slapd service.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":32841,"name":"Reinildes Oliveira","display_name":"Rei Oliveira","email":"Reinildes.JoseMateusOliveira@windriver.com","username":"rjosemat"},"change_message_id":"686eba09e5e9eab530a1405410beeee7175be15e","unresolved":true,"context_lines":[{"line_number":222,"context_line":"      owner   \u003d\u003e $ldap_user,"},{"line_number":223,"context_line":"      group   \u003d\u003e $ldap_group,"},{"line_number":224,"context_line":"      mode    \u003d\u003e \u00270644\u0027,"},{"line_number":225,"context_line":"      content \u003d\u003e $secure_cert,"},{"line_number":226,"context_line":"    }"},{"line_number":227,"context_line":"    -\u003e file { \u0027ldap-key\u0027:"},{"line_number":228,"context_line":"      ensure  \u003d\u003e present,"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"b26dbc81_1ce5dcd0","line":225,"updated":"2022-08-23 20:00:27.000000000","message":"Seems like the cert and key are being passed here as parameters. Where are those parameters coming from?","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":32841,"name":"Reinildes Oliveira","display_name":"Rei Oliveira","email":"Reinildes.JoseMateusOliveira@windriver.com","username":"rjosemat"},"change_message_id":"f84b39cda07f82362599ddc5f806ebac3f7a4388","unresolved":false,"context_lines":[{"line_number":222,"context_line":"      owner   \u003d\u003e $ldap_user,"},{"line_number":223,"context_line":"      group   \u003d\u003e $ldap_group,"},{"line_number":224,"context_line":"      mode    \u003d\u003e \u00270644\u0027,"},{"line_number":225,"context_line":"      content \u003d\u003e $secure_cert,"},{"line_number":226,"context_line":"    }"},{"line_number":227,"context_line":"    -\u003e file { \u0027ldap-key\u0027:"},{"line_number":228,"context_line":"      ensure  \u003d\u003e present,"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"960f7d6b_e2eccb9a","line":225,"in_reply_to":"04a7f77c_68daa3b8","updated":"2022-08-25 22:14:40.000000000","message":"Ack","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":32841,"name":"Reinildes Oliveira","display_name":"Rei Oliveira","email":"Reinildes.JoseMateusOliveira@windriver.com","username":"rjosemat"},"change_message_id":"6904f41a93a986f2a60fde3be220306a8ef2c895","unresolved":false,"context_lines":[{"line_number":222,"context_line":"      owner   \u003d\u003e $ldap_user,"},{"line_number":223,"context_line":"      group   \u003d\u003e $ldap_group,"},{"line_number":224,"context_line":"      mode    \u003d\u003e \u00270644\u0027,"},{"line_number":225,"context_line":"      content \u003d\u003e $secure_cert,"},{"line_number":226,"context_line":"    }"},{"line_number":227,"context_line":"    -\u003e file { \u0027ldap-key\u0027:"},{"line_number":228,"context_line":"      ensure  \u003d\u003e present,"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"47dddf96_ef43a68b","line":225,"in_reply_to":"08ea6dc1_02c43a7b","updated":"2022-08-23 20:50:45.000000000","message":"I think you probably need to add a depends-on here then to point to that change","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":32841,"name":"Reinildes Oliveira","display_name":"Rei Oliveira","email":"Reinildes.JoseMateusOliveira@windriver.com","username":"rjosemat"},"change_message_id":"bdc6a24fd37c8253ebeea1e66ef2843b2c944dfc","unresolved":true,"context_lines":[{"line_number":222,"context_line":"      owner   \u003d\u003e $ldap_user,"},{"line_number":223,"context_line":"      group   \u003d\u003e $ldap_group,"},{"line_number":224,"context_line":"      mode    \u003d\u003e \u00270644\u0027,"},{"line_number":225,"context_line":"      content \u003d\u003e $secure_cert,"},{"line_number":226,"context_line":"    }"},{"line_number":227,"context_line":"    -\u003e file { \u0027ldap-key\u0027:"},{"line_number":228,"context_line":"      ensure  \u003d\u003e present,"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"8dfb9e89_5f154a49","line":225,"in_reply_to":"47dddf96_ef43a68b","updated":"2022-08-23 20:52:34.000000000","message":"Depends-on to config","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"b38a1ddb188f5cd0a3e1e1e7ba0a85f296a0e01e","unresolved":true,"context_lines":[{"line_number":222,"context_line":"      owner   \u003d\u003e $ldap_user,"},{"line_number":223,"context_line":"      group   \u003d\u003e $ldap_group,"},{"line_number":224,"context_line":"      mode    \u003d\u003e \u00270644\u0027,"},{"line_number":225,"context_line":"      content \u003d\u003e $secure_cert,"},{"line_number":226,"context_line":"    }"},{"line_number":227,"context_line":"    -\u003e file { \u0027ldap-key\u0027:"},{"line_number":228,"context_line":"      ensure  \u003d\u003e present,"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"04a7f77c_68daa3b8","line":225,"in_reply_to":"8dfb9e89_5f154a49","updated":"2022-08-23 21:12:26.000000000","message":"See my reply to commit message.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"ac067c48095c321d4aa793f4c464ad722575aef3","unresolved":false,"context_lines":[{"line_number":222,"context_line":"      owner   \u003d\u003e $ldap_user,"},{"line_number":223,"context_line":"      group   \u003d\u003e $ldap_group,"},{"line_number":224,"context_line":"      mode    \u003d\u003e \u00270644\u0027,"},{"line_number":225,"context_line":"      content \u003d\u003e $secure_cert,"},{"line_number":226,"context_line":"    }"},{"line_number":227,"context_line":"    -\u003e file { \u0027ldap-key\u0027:"},{"line_number":228,"context_line":"      ensure  \u003d\u003e present,"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"08ea6dc1_02c43a7b","line":225,"in_reply_to":"b26dbc81_1ce5dcd0","updated":"2022-08-23 20:25:45.000000000","message":"The cert and key come from platform::ldap::params::secure_cert and platform::ldap::params::secure_key, which in turn come from puppet hieradata secure_system.yaml(generated by sysinv puppet plugin).","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":31646,"name":"Carmen Rata","email":"carmen.rata@windriver.com","username":"crata"},"change_message_id":"7b987eb2e67c805340f4f6bd884968b88096432a","unresolved":true,"context_lines":[{"line_number":236,"context_line":"      command \u003d\u003e \"ldapmodify -D ${dn} -w \\\"${admin_pw}\\\" -xH ldap:/// -f ${slapd_etc_path}/certs.ldif\","},{"line_number":237,"context_line":"    }"},{"line_number":238,"context_line":"  }"},{"line_number":239,"context_line":"}"},{"line_number":240,"context_line":""},{"line_number":241,"context_line":"class platform::ldap::secure::runtime"},{"line_number":242,"context_line":"  inherits ::platform::ldap::params {"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"11f494f3_c7e8b11d","line":239,"updated":"2022-08-23 21:32:31.000000000","message":"Why did you choose to refactor the previous code that was working and had less footprint? I find redundant setting for mode in this implementation.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"26a0317494f72025cfe28492153bd965a333b4c8","unresolved":true,"context_lines":[{"line_number":236,"context_line":"      command \u003d\u003e \"ldapmodify -D ${dn} -w \\\"${admin_pw}\\\" -xH ldap:/// -f ${slapd_etc_path}/certs.ldif\","},{"line_number":237,"context_line":"    }"},{"line_number":238,"context_line":"  }"},{"line_number":239,"context_line":"}"},{"line_number":240,"context_line":""},{"line_number":241,"context_line":"class platform::ldap::secure::runtime"},{"line_number":242,"context_line":"  inherits ::platform::ldap::params {"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"63dc434f_839f5a85","line":239,"in_reply_to":"11f494f3_c7e8b11d","updated":"2022-08-24 18:34:52.000000000","message":"Since with the current implementation, secure openldap won\u0027t have certificate and key files when controller-1 becomes active controller, so sssd won\u0027t be able to connect to secure openldap (no certificate error).","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":31646,"name":"Carmen Rata","email":"carmen.rata@windriver.com","username":"crata"},"change_message_id":"17c37cddceed137fd387d8060ea0ff4520a2ed1b","unresolved":false,"context_lines":[{"line_number":236,"context_line":"      command \u003d\u003e \"ldapmodify -D ${dn} -w \\\"${admin_pw}\\\" -xH ldap:/// -f ${slapd_etc_path}/certs.ldif\","},{"line_number":237,"context_line":"    }"},{"line_number":238,"context_line":"  }"},{"line_number":239,"context_line":"}"},{"line_number":240,"context_line":""},{"line_number":241,"context_line":"class platform::ldap::secure::runtime"},{"line_number":242,"context_line":"  inherits ::platform::ldap::params {"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"5acc6a82_d20f97b1","line":239,"in_reply_to":"63dc434f_839f5a85","updated":"2022-08-25 20:29:49.000000000","message":"Ack","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":31646,"name":"Carmen Rata","email":"carmen.rata@windriver.com","username":"crata"},"change_message_id":"7b987eb2e67c805340f4f6bd884968b88096432a","unresolved":true,"context_lines":[{"line_number":244,"context_line":""},{"line_number":245,"context_line":"  class { \u0027::platform::ldap::secure::config\u0027:}"},{"line_number":246,"context_line":"  -\u003e exec { \u0027restart sssd to connect to secure ldap\u0027:"},{"line_number":247,"context_line":"    command \u003d\u003e \u0027/usr/bin/systemctl restart sssd.service\u0027,"},{"line_number":248,"context_line":"    onlyif  \u003d\u003e \"test \u0027${::osfamily }\u0027 \u003d\u003d \u0027Debian\u0027\","},{"line_number":249,"context_line":"  }"},{"line_number":250,"context_line":"}"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"b59c7f82_b9f3f06b","line":247,"updated":"2022-08-23 21:32:31.000000000","message":"you would restart slapd service, not sssd.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":31646,"name":"Carmen Rata","email":"carmen.rata@windriver.com","username":"crata"},"change_message_id":"712609db9a4f61e33461e7eb3a3a8581b579d360","unresolved":true,"context_lines":[{"line_number":244,"context_line":""},{"line_number":245,"context_line":"  class { \u0027::platform::ldap::secure::config\u0027:}"},{"line_number":246,"context_line":"  -\u003e exec { \u0027restart sssd to connect to secure ldap\u0027:"},{"line_number":247,"context_line":"    command \u003d\u003e \u0027/usr/bin/systemctl restart sssd.service\u0027,"},{"line_number":248,"context_line":"    onlyif  \u003d\u003e \"test \u0027${::osfamily }\u0027 \u003d\u003d \u0027Debian\u0027\","},{"line_number":249,"context_line":"  }"},{"line_number":250,"context_line":"}"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"d5b30459_ee76a2dc","line":247,"in_reply_to":"1fe294f1_9f268e14","updated":"2022-08-24 21:38:49.000000000","message":"Are we talking here about openldap certificate and key? The sssd.conf contains the ca certificate from /etc/ssl/certs/ca-certificates.crt. If the ca cert does not change we do not need to restart sssd service.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"c24859b80bcb2e0ab903896549474e8317b4a33f","unresolved":false,"context_lines":[{"line_number":244,"context_line":""},{"line_number":245,"context_line":"  class { \u0027::platform::ldap::secure::config\u0027:}"},{"line_number":246,"context_line":"  -\u003e exec { \u0027restart sssd to connect to secure ldap\u0027:"},{"line_number":247,"context_line":"    command \u003d\u003e \u0027/usr/bin/systemctl restart sssd.service\u0027,"},{"line_number":248,"context_line":"    onlyif  \u003d\u003e \"test \u0027${::osfamily }\u0027 \u003d\u003d \u0027Debian\u0027\","},{"line_number":249,"context_line":"  }"},{"line_number":250,"context_line":"}"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"01cffd3d_e8a594ab","line":247,"in_reply_to":"5f8e19c0_3358a094","updated":"2022-08-26 13:38:33.000000000","message":"Done","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"e447b01d6ad75e24630c1f3834c7baf97c07874f","unresolved":true,"context_lines":[{"line_number":244,"context_line":""},{"line_number":245,"context_line":"  class { \u0027::platform::ldap::secure::config\u0027:}"},{"line_number":246,"context_line":"  -\u003e exec { \u0027restart sssd to connect to secure ldap\u0027:"},{"line_number":247,"context_line":"    command \u003d\u003e \u0027/usr/bin/systemctl restart sssd.service\u0027,"},{"line_number":248,"context_line":"    onlyif  \u003d\u003e \"test \u0027${::osfamily }\u0027 \u003d\u003d \u0027Debian\u0027\","},{"line_number":249,"context_line":"  }"},{"line_number":250,"context_line":"}"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"1fe294f1_9f268e14","line":247,"in_reply_to":"b59c7f82_b9f3f06b","updated":"2022-08-24 18:36:03.000000000","message":"As you mentioned before (and verified by test), secure openldap doesn\u0027t need to restart here. But since the certificate and key are changed (triggered by certificate renewal), sssd will lose connection to secure openldap (since openldap is using new certificate). That\u0027s why the sssd needs to be restart here to reconnect.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"42efa93b6421ec1acc57d08e59914a7dca64cb53","unresolved":true,"context_lines":[{"line_number":244,"context_line":""},{"line_number":245,"context_line":"  class { \u0027::platform::ldap::secure::config\u0027:}"},{"line_number":246,"context_line":"  -\u003e exec { \u0027restart sssd to connect to secure ldap\u0027:"},{"line_number":247,"context_line":"    command \u003d\u003e \u0027/usr/bin/systemctl restart sssd.service\u0027,"},{"line_number":248,"context_line":"    onlyif  \u003d\u003e \"test \u0027${::osfamily }\u0027 \u003d\u003d \u0027Debian\u0027\","},{"line_number":249,"context_line":"  }"},{"line_number":250,"context_line":"}"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"5f8e19c0_3358a094","line":247,"in_reply_to":"d5b30459_ee76a2dc","updated":"2022-08-25 13:45:08.000000000","message":"You are right. I\u0027m testing to verify that the restart is not needed. Will update the change after that.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":31646,"name":"Carmen Rata","email":"carmen.rata@windriver.com","username":"crata"},"change_message_id":"7b987eb2e67c805340f4f6bd884968b88096432a","unresolved":true,"context_lines":[{"line_number":246,"context_line":"  -\u003e exec { \u0027restart sssd to connect to secure ldap\u0027:"},{"line_number":247,"context_line":"    command \u003d\u003e \u0027/usr/bin/systemctl restart sssd.service\u0027,"},{"line_number":248,"context_line":"    onlyif  \u003d\u003e \"test \u0027${::osfamily }\u0027 \u003d\u003d \u0027Debian\u0027\","},{"line_number":249,"context_line":"  }"},{"line_number":250,"context_line":"}"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"4d1d3501_591d7944","line":249,"updated":"2022-08-23 21:32:31.000000000","message":"This is very interesting that you do not restart slapd (see previous code) after line 121 but you do it here.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"26a0317494f72025cfe28492153bd965a333b4c8","unresolved":true,"context_lines":[{"line_number":246,"context_line":"  -\u003e exec { \u0027restart sssd to connect to secure ldap\u0027:"},{"line_number":247,"context_line":"    command \u003d\u003e \u0027/usr/bin/systemctl restart sssd.service\u0027,"},{"line_number":248,"context_line":"    onlyif  \u003d\u003e \"test \u0027${::osfamily }\u0027 \u003d\u003d \u0027Debian\u0027\","},{"line_number":249,"context_line":"  }"},{"line_number":250,"context_line":"}"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"f1176477_bca6e88f","line":249,"in_reply_to":"4d1d3501_591d7944","updated":"2022-08-24 18:34:52.000000000","message":"I don\u0027t restart slapd here, but restart sssd.","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"},{"author":{"_account_id":28676,"name":"Andy Ning","email":"andy.ning@windriver.com","username":"andy.wrs"},"change_message_id":"c24859b80bcb2e0ab903896549474e8317b4a33f","unresolved":false,"context_lines":[{"line_number":246,"context_line":"  -\u003e exec { \u0027restart sssd to connect to secure ldap\u0027:"},{"line_number":247,"context_line":"    command \u003d\u003e \u0027/usr/bin/systemctl restart sssd.service\u0027,"},{"line_number":248,"context_line":"    onlyif  \u003d\u003e \"test \u0027${::osfamily }\u0027 \u003d\u003d \u0027Debian\u0027\","},{"line_number":249,"context_line":"  }"},{"line_number":250,"context_line":"}"}],"source_content_type":"text/x-puppet","patch_set":2,"id":"3ee8defb_21d0aa6c","line":249,"in_reply_to":"f1176477_bca6e88f","updated":"2022-08-26 13:38:33.000000000","message":"Done","commit_id":"e01ea230d99b4135a52caa357738dbb952e43f0f"}]}
