Description
When -etcd-cafile is specified without a client cert/key, locksmith fails with the error:
$ locksmithctl -etcd-cafile=/etc/ssl/certs/ca-certificates.crt status
Error initializing etcd client: open : no such file or directory
I've configured etcd with TLS using self-signed certificates but not TLS client authentication. locksmith seems to be looking for a certificate and key, even though these options are not applicable.
Impact
Error message is confusing, because it relates to an unrelated command line option.
Environment and steps to reproduce
- Set-up: Flatcar Linux 3374.2.2
- Task: Configuring locksmith with TLS communication and server-only authentication
- Action(s):
a. locksmithctl -etcd-cafile=/etc/ssl/certs/ca-certificates.crt status
- Error:
Error initializing etcd client: open : no such file or directory
Expected behavior
locksmith uses the specified CA to authenticate the server without client authentication.
Additional information
N/A.
Description
When
-etcd-cafileis specified without a client cert/key, locksmith fails with the error:I've configured etcd with TLS using self-signed certificates but not TLS client authentication. locksmith seems to be looking for a certificate and key, even though these options are not applicable.
Impact
Error message is confusing, because it relates to an unrelated command line option.
Environment and steps to reproduce
a. locksmithctl -etcd-cafile=/etc/ssl/certs/ca-certificates.crt status
Error initializing etcd client: open : no such file or directoryExpected behavior
locksmith uses the specified CA to authenticate the server without client authentication.
Additional information
N/A.