Skip to content

Add notes on the PKI cert generation forwarding regression#13815

Merged
sgmiller merged 5 commits intomainfrom
pki-forward-bug-note
Jan 27, 2022
Merged

Add notes on the PKI cert generation forwarding regression#13815
sgmiller merged 5 commits intomainfrom
pki-forward-bug-note

Conversation

@sgmiller
Copy link
Copy Markdown
Collaborator

No description provided.

@@ -0,0 +1,10 @@
## PKI Certificate Generation Forwarding Regression

A bug introduced in Vault 1.8 causes certificates issue by the PKI secrets engine made on a performance
Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
A bug introduced in Vault 1.8 causes certificates issue by the PKI secrets engine made on a performance
A bug introduced in Vault 1.8 causes certificates generation requests via the PKI secrets engine made on a performance

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think "causes certificate generation requests via" (get rid of the pluralization of "certificates")?

## PKI Certificate Generation Forwarding Regression

A bug introduced in Vault 1.8 causes certificates issue by the PKI secrets engine made on a performance
secondary node to be forwarded to a Vault cluster's primary node. This affects horizontal scalability, but
Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't expect the horizontal scalability is the real issue most users, it's more about the certs/CRLs being in the wrong place. If we do want to retain this bit, I might expand it a little - not everyone's going to follow what we mean by horizontal scalability.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Okay, I'll just drop that part.

@mladlow
Copy link
Copy Markdown
Contributor

mladlow commented Jan 27, 2022

@sgmiller I changed the label to "backport/website" which will open and automerge a PR to stable website and open a PR against release/1.9 for versioned docs - could you please make sure to merge the release/1.9 PR? Those don't automerge.

@sgmiller
Copy link
Copy Markdown
Collaborator Author

Revision 2

@sgmiller sgmiller requested a review from ncabatoff January 27, 2022 22:06
@vercel vercel bot temporarily deployed to Preview – vault-storybook January 27, 2022 22:09 Inactive
Copy link
Copy Markdown
Contributor

@mladlow mladlow left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

By my read this resolves @ncabatoff's comments but I don't necessarily want to speak for him. Anyway, I didn't understand this issue before reading this note and I now understand it much better, so from my perspective this is good.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants