Skip to content

24.3 Backport of #69582 - more advanced SSL options for Keeper internal communication#496

Merged
Enmk merged 2 commits into
customizations/24.3.11from
backports/24.3/69582_more_advanced_SSL_options_for_Keeper
Oct 14, 2024
Merged

24.3 Backport of #69582 - more advanced SSL options for Keeper internal communication#496
Enmk merged 2 commits into
customizations/24.3.11from
backports/24.3/69582_more_advanced_SSL_options_for_Keeper

Conversation

@Enmk

@Enmk Enmk commented Oct 9, 2024

Copy link
Copy Markdown
Member

Changelog category (leave one):

  • Improvement

Changelog entry (a user-readable short description of the changes that goes to CHANGELOG.md):

Support more advanced SSL options for Keeper's internal communication (e.g. private keys with passphrase) (ClickHouse#69582 by @antonio2368)

…-support

Support more advanced SSL options for Keeper internal communication
@altinity-robot

altinity-robot commented Oct 9, 2024

Copy link
Copy Markdown
Collaborator

This is an automated comment for commit 81249e1 with description of existing statuses. It's updated for the latest CI running

❌ Click here to open a full report in a separate page

Check nameDescriptionStatus
CI runningA meta-check that indicates the running CI. Normally, it's in success or pending state. The failed status indicates some problems with the PR⏳ pending
ClickHouse build checkBuilds ClickHouse in various configurations for use in further steps. You have to fix the builds that fail. Build logs often has enough information to fix the error, but you might have to reproduce the failure locally. The cmake options can be found in the build log, grepping for cmake. Use these options and follow the general build process⏳ pending
Docker keeper imageThe check to build and optionally push the mentioned image to docker hub❌ failure
Integration testsThe integration tests report. In parenthesis the package type is given, and in square brackets are the optional part/total tests❌ failure
Mergeable CheckChecks if all other necessary checks are successful❌ failure
Stateless testsRuns stateless functional tests for ClickHouse binaries built in various configurations -- release, debug, with sanitizers, etc❌ failure
Stress testRuns stateless functional tests concurrently from several clients to detect concurrency-related errors❌ failure
Successful checks
Check nameDescriptionStatus
Compatibility checkChecks that clickhouse binary runs on distributions with old libc versions. If it fails, ask a maintainer for help✅ success
Docker server imageThe check to build and optionally push the mentioned image to docker hub✅ success
Install packagesChecks that the built packages are installable in a clear environment✅ success
Ready for releaseThere's no description for the check yet, please add it to tests/ci/ci_config.py:CHECK_DESCRIPTIONS✅ success
Stateful testsRuns stateful functional tests for ClickHouse binaries built in various configurations -- release, debug, with sanitizers, etc✅ success


nodes[0].start_clickhouse(expected_to_fail=True)
nodes[0].wait_for_log_line(
"OpenSSLException: EVPKey::loadKey.*error:0480006C:PEM routines::no start line",

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In 24.3 we are still using BoringSSL, so the error message is a bit different:
OpenSSLException: EVPKey::loadKey(string): error:0900006e:PEM routines:OPENSSL_internal:NO_START_LINE

@Enmk Enmk merged commit b8ee970 into customizations/24.3.11 Oct 14, 2024
@Enmk Enmk mentioned this pull request Nov 1, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants