Keystone, Neutron and Designate: TLS trust store coordination for external DNS updates?
0 reputation · 21 Mar 2022, 13:21 UTC
The goal is to determine whether OpenStack services involved in the Neutron‑Designate DNS update path—Keystone for authentication, Neutron for triggering the update, and Designate for contacting the external DNS provider—can be configured to use a common TLS trust store when validating the certificates of those external DNS endpoints.
Current documentation indicates that each service relies on its own trust store or the system default, with no centralized option to enforce certificate validation across the chain. This leaves operators uncertain about whether manual CA injection into each service’s /etc/ssl/certs (or equivalent) is required, and how behavior varies between releases such as Wallaby, Zed, or earlier.
- Is there a shared configuration mechanism (e.g., a keystone‑wide TLS option or a designate‑neutron plugin) that allows all three services to validate external DNS certificates using a single trust store?
- If such a mechanism does not exist, what is the recommended practice for ensuring consistent certificate validation without duplicating CA bundles in each service’s configuration?
- Are there any release‑specific flags, environment variables, or configuration files introduced in recent OpenStack versions that enable centralized TLS verification for the Designate‑Neutron integration?