Salt Minion Windows Installer uses openssl and own cert chain #67301
Replies: 26 comments
|
We currently bundle OpenSSL 1.0.2n and we package @dwoz ? |
|
@mruepp Could you try installing or from the master with: If that works, we'll add that dependency to the Salt installation for future versions. |
|
ZD-2644 |
|
I can confirm that installing |
|
The only thing I can think of to do here is a separate Salt build that uses the system certificate store using |
|
Can you expand on why this would be (or should be) a separate build? |
|
This fix is causing issues with our tests. We'll need to do a deep dive into the On a Windows system without
|
|
NOTE: If you install |
|
So, Python has been using the Windows Certificate Store since 2.7.9 and 3.4. (see here) The problem is another dependency that Salt is using; Tornado. certifi is a requirement for Tornado versions <5. Starting with Tornado 5.0 they dropped the certifi requirement. (see here) However, Salt on Py3 is pinned to using versions of Tornado greater than 4.2.1 and less than 5 (see here). Support for Tornado 5 will be implemented in the Fluorine release (see here). Salt on Py2 does support Tornado 5. So, theoretically, you could install the Py2 version of Salt, uninstall certifi and upgrade Tornado to version 5.1 in the salt installation to work around this issue. Bottom line, this issue should be fixed in Fluorine by updating support for Tornado 5 on Py3. |
|
This is dependent on the work being done here: |
|
@dwoz Yes, correct. Once that is done, we'll need to change the deps for the Py3 windows package to use tornado 5. |
|
Tornado 5.0 support #51883 should fix this; Pending testing and validation post Tornado 5.0 fix |
|
Once we're able to use Tornado 5, we'll possibly remove the certifi requirement. |
|
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. If this issue is closed prematurely, please leave a comment and we will gladly reopen the issue. |
|
not stale yet. |
|
Thank you for updating this issue. It is no longer marked as stale. |
|
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. If this issue is closed prematurely, please leave a comment and we will gladly reopen the issue. |
|
@sagetherage and @twangboy Should this marked both as |
|
Thank you for updating this issue. It is no longer marked as stale. |
|
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. If this issue is closed prematurely, please leave a comment and we will gladly reopen the issue. |
|
Thank you for updating this issue. It is no longer marked as stale. |
|
I re-added the Sodium label because the work on Tornado 5 will fix this issue. |
|
Descoping from |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Description of Issue/Question
In Windows we have to add self signed ca chain to the salt minion installer cert.pem
We want salt to use the windows truststore certs which are delivered by active directory, basically use schannel transport or be able to configure this on a case to case base.
This is a problem with all self signed ca environments. Often on Linux we deploy cert chains with salt or other mechanisms, in Windows the cachains are usually as point of truth in AD and deployed with AD
Setup
(Please provide relevant configs and/or SLS files (Be sure to remove sensitive info).)
Default salt minion python 3 amd64 installer
Steps to Reproduce Issue
(Include debug logs if possible and relevant.)
use file.managed from https source with self signed cert will throw ssl not verified error, also archive.extracted
Versions Report
`
Salt Version:
Salt: 2017.7.4
Dependency Versions:
cffi: 1.6.0
cherrypy: Not Installed
dateutil: Not Installed
docker-py: Not Installed
gitdb: Not Installed
gitpython: Not Installed
ioflo: Not Installed
Jinja2: 2.7.2
libgit2: 0.24.6
libnacl: Not Installed
M2Crypto: Not Installed
Mako: Not Installed
msgpack-pure: Not Installed
msgpack-python: 0.4.6
mysql-python: Not Installed
pycparser: 2.14
pycrypto: 2.6.1
pycryptodome: Not Installed
pygit2: 0.24.2
Python: 2.7.5 (default, Aug 4 2017, 00:39:18)
python-gnupg: Not Installed
PyYAML: 3.11
PyZMQ: 15.3.0
RAET: Not Installed
smmap: Not Installed
timelib: Not Installed
Tornado: 4.2.1
ZMQ: 4.1.4
System Versions:
dist: centos 7.4.1708 Core
locale: UTF-8
machine: x86_64
release: 3.10.0-693.21.1.el7.x86_64
system: Linux
version: CentOS Linux 7.4.1708 Core
`
All reactions