Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix OpenSSL system CA certificate issue in indico image #412

Merged
merged 2 commits into from
Jun 5, 2024

Conversation

weiiwang01
Copy link
Contributor

In the current Indico image, the /etc/ssl/certs/ca-certificates.crt file is copied to the same location inside the Indico rock container. However, this is not a location recognized by OpenSSL as the system CA certificates. Consequently, this causes Python, which depends on OpenSSL, to fail in establishing TLS connections, particularly as observed in the smtplib library.

Update the rockcraft.yaml file to copy the ca-certificates.crt to /usr/lib/ssl/cert.pem, which is OpenSSL's default SSL certificate file on Ubuntu.

@weiiwang01 weiiwang01 requested a review from a team as a code owner June 5, 2024 12:11
Copy link
Contributor

github-actions bot commented Jun 5, 2024

Test coverage for 85b7990

Name                       Stmts   Miss Branch BrPart  Cover   Missing
----------------------------------------------------------------------
src/charm.py                 329      9     82      7    96%   631, 672-673, 761->777, 763->772, 772->777, 785-786, 825, 858->exit, 896-902
src/database_observer.py      32      0      4      0   100%
src/s3_observer.py            17      0      0      0   100%
src/saml_observer.py          14      0      0      0   100%
src/smtp_observer.py          15      0      0      0   100%
src/state.py                  73      0     10      0   100%
----------------------------------------------------------------------
TOTAL                        480      9     96      7    97%

Static code analysis report

Run started:2024-06-05 12:49:58.154962

Test results:
  No issues identified.

Code scanned:
  Total lines of code: 2970
  Total lines skipped (#nosec): 2
  Total potential issues skipped due to specifically being disabled (e.g., #nosec BXXX): 0

Run metrics:
  Total issues (by severity):
  	Undefined: 0
  	Low: 0
  	Medium: 0
  	High: 0
  Total issues (by confidence):
  	Undefined: 0
  	Low: 0
  	Medium: 0
  	High: 0
Files skipped (0):

@arturo-seijas arturo-seijas merged commit 231a5fb into main Jun 5, 2024
25 checks passed
@arturo-seijas arturo-seijas deleted the openssl-certs branch June 5, 2024 13:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants