Skip to content

locksmith fails when -etcd-cafile is specified #948

Description

@adborden

Description

When -etcd-cafile is specified without a client cert/key, locksmith fails with the error:

$ locksmithctl -etcd-cafile=/etc/ssl/certs/ca-certificates.crt status
Error initializing etcd client: open : no such file or directory

I've configured etcd with TLS using self-signed certificates but not TLS client authentication. locksmith seems to be looking for a certificate and key, even though these options are not applicable.

Impact

Error message is confusing, because it relates to an unrelated command line option.

Environment and steps to reproduce

  1. Set-up: Flatcar Linux 3374.2.2
  2. Task: Configuring locksmith with TLS communication and server-only authentication
  3. Action(s):
    a. locksmithctl -etcd-cafile=/etc/ssl/certs/ca-certificates.crt status
  4. Error: Error initializing etcd client: open : no such file or directory

Expected behavior

locksmith uses the specified CA to authenticate the server without client authentication.

Additional information

N/A.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/bugSomething isn't working

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions