Cisco NX-OS: gNOI endpoint does not support `LoadCertificateAuthorityBundleRequest`
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 35/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Necesita aclaración
- Estado de actividad
- Tranquilo
- Stack tecnológico
- go, grpc
- Área
- networking, security
Línea de trabajo
Comienza revisando el endpoint gNOI LoadCertificateAuthorityBundleRequest y los puntos de entrada existentes del operador para la gestión de certificados de Cisco NX-OS. Compara el enfoque propuesto de bootscript inicial y NXAPI con el flujo de provisioning actual. La tarea estará terminada cuando el repositorio tenga una forma definida y probada de instalar o rotar certificados de CA a pesar de la falta de soporte de gNOI por parte del proveedor.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Problem Statement
The Cisco NXOS Generic Network Operations Interface (gNOI) lacks support for the LoadCertificateAuthorityBundleRequest endpoint, which prevents the installation of Certificate Authority (CA) certificates. This is a major roadblock when implementing gRPC with Mutual TLS authentication, as it requires the CA certificate to be installed on devices.
Vendor Acknowledgement
Cisco has acknowledged this problem and filled CSCwr90920 (login required); however, the bug report refers to LoadCertificteBundleRequest, which does not exist in the gNOI specification. A tentative ETA of end of 2026 for release 10.7.2 was suggested.
Proposed Solution
As an interim solution, we propose using the initial bootscript to deploy the CA bundle and then installing/rotating certificates via NXAPI (CLI over HTTP). This approach allows for automation of certificate management while circumventing the limitation in Cisco's gNOI implementation.
- Lenguaje dominante
- Go
- Estrellas
- 12
- Forks
- 9
- Merge medio
- 3 d 15 h
- PR fusionados (30 d)
- 46
Preparar el entorno
- Incluye un Dockerfile o un archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de ironcore-dev/network-operator
-
area/switch-automation
Dificultad 5/5 Más de una semana Aptitud para principiantes 45/100
ironcore-dev/network-operator#440 · 4 comentarios ·
Los mantenedores suelen responder en 1 día
-
area/switch-automation firmware-bug vendor/cisco
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
ironcore-dev/network-operator#282 · 7 comentarios ·
Los mantenedores suelen responder en 1 día
-
Introduce a generic reconciler abstraction to reduce controller boilerplateQuizá libre de nuevo @felix-kaestner la tomó hace 198 días y no hay ningún pull request abierto. Abiertoarea/switch-automation enhancement
ironcore-dev/network-operator#257 · 3 comentarios · 1 asignado ·
Los mantenedores suelen responder en 1 día
-
area/switch-automation firmware-bug plattform/iosxr vendor/cisco
Dificultad 3/5 1-2 días Aptitud para principiantes 52/100
ironcore-dev/network-operator#178 · 3 comentarios · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
area/switch-automation firmware-bug platform/nx vendor/cisco
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
ironcore-dev/network-operator#171 · 3 comentarios ·
Los mantenedores suelen responder en 1 día
Todos los issues de ironcore-dev/network-operator
Issues similares
-
Discriminator mapping keys are listed in a random orderPosiblemente ocupada @reuvenharrison la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
Idle compaction monitors LIST the replica every tick when the newest destination file spans more than one TXIDPosiblemente ocupada @pishuv la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
benbjohnson/litestream#1563 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
agent-research agent-review-finding chore
Dificultad 2/5 1-3 horas Aptitud para principiantes 66/100
jordansmall/spindrift#4922 ·
Los mantenedores suelen responder en 1 día
-
gcsartifact: deleting a missing version returns an errorPosiblemente ocupada @ktsoator la tomó hoy. Abiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 2 días