etcd-io / etcd-io/etcd

ETCD doesn't automatically load changes to ca bundles for peer-trusted-ca-file or trusted-ca-file

Open
#11,555 43 comments 7 reactions 0 assignees View on GitHub
stage/triaged type/feature
Dominant language
Go
Stars
52.3k
Forks
10.5k
Avg merge
3d 3h
Merged PRs (30d)
42

Description

Etcd cannot handle cert bundles in the `peer-trusted-ca-file` or `trusted-ca-file` section. Without the ability to handle CA bundles, it is impossible to do a 0 downtime approach to CA rotation without resigning all active client and server certs at once.

If a CA bundle was allowed: A new CA could be created and made valid in all components in the first interation. Then client certs can be resigned with the new CA since the server components have the new CA plus the old CA in it's trust bundle. Once all clients have been resigned and downloaded the old + new CA the server components can be signed with the new CA and then the old CA can be effectively removed.

It appears this was meant to be fixed but I am able to replicate the issue in an etcd deployment today.
I will expose all the certs and command line configurations in this issue so the exact steps can be replicated.

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the issue in an etcd deployment using the peer-trusted-ca-file and trusted-ca-file command-line settings, then trace how those trust files are loaded. Compare the behavior with the CA-bundle rotation described in the issue. Done means both settings accept updated CA bundles without resigning all active certificates at once, with coverage for the reported scenario.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
distributed-systems, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.