# Enabling peerVertificationRules with self-signed certificate on ocp/k8s

**URL:** <https://forums.foundationdb.org/t/enabling-peervertificationrules-with-self-signed-certificate-on-ocp-k8s/3187>\
**Category:** Running FoundationDB\
**Created:** [February 18, 2022, 5:53pm UTC](https://forums.foundationdb.org/t/enabling-peervertificationrules-with-self-signed-certificate-on-ocp-k8s/3187 "2022-02-18T17:53:11Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![tangerine](https://sea1.discourse-cdn.com/foundationdb/user_avatar/forums.foundationdb.org/tangerine/32/1084_2.png) [@tangerine](https://forums.foundationdb.org/u/tangerine)\
**Post date:** [February 18, 2022, 5:53pm UTC](https://forums.foundationdb.org/t/enabling-peervertificationrules-with-self-signed-certificate-on-ocp-k8s/3187/1 "2022-02-18T17:53:11Z")

</div>

Hi,  
I am trying to enable the peerVerificationrules following the doc in the GitHub on operator. One thing that I am trying is to use self-signed certificate. If I use the self-signed certification to enable TLS only without the peerverifiationRules, the cluster comes up with TLS, everything seems to work ok. But as soon as I enable the rules, I got “Unauthorized Error” and I am not sure what need to be done if I want to use the self-signed certificate. Can anyone help?

---

<div class="post-metadata">

**Author:** ![john\_brownlee](https://sea1.discourse-cdn.com/foundationdb/user_avatar/forums.foundationdb.org/john_brownlee/32/22_2.png) [@john\_brownlee](https://forums.foundationdb.org/u/john_brownlee)\
**Post date:** [February 21, 2022, 4:07pm UTC](https://forums.foundationdb.org/t/enabling-peervertificationrules-with-self-signed-certificate-on-ocp-k8s/3187/2 "2022-02-21T16:07:43Z")

</div>

It sounds like the system is rejecting the certificate based on the configured rules. Can you share more details about the certificate and verification rules you are using?

---

<div class="post-metadata">

**Author:** ![tangerine](https://sea1.discourse-cdn.com/foundationdb/user_avatar/forums.foundationdb.org/tangerine/32/1084_2.png) [@tangerine](https://forums.foundationdb.org/u/tangerine)\
**Post date:** [February 22, 2022, 3:51pm UTC](https://forums.foundationdb.org/t/enabling-peervertificationrules-with-self-signed-certificate-on-ocp-k8s/3187/3 "2022-02-22T15:51:40Z")

</div>

Hi John,  
Here is the rule I used: peerVerificationRules: “Check.Valid=1”

And here is the openssl x509 output on the meta data on the ca.crt:  
Certificate:  
Data:  
Version: 3 (0x2)  
Serial Number:  
a7:e4:ec:81:6f:aa:b9:30:57:38:a1:eb:63:d4:d8:e6  
Signature Algorithm: sha256WithRSAEncryption  
Issuer: CN = cs-ca-certificate  
Validity  
Not Before: Sep 20 15:33:56 2021 GMT  
Not After : Sep 20 15:33:56 2023 GMT  
Subject: CN = cs-ca-certificate  
Subject Public Key Info:  
Public Key Algorithm: rsaEncryption  
RSA Public-Key: (2048 bit)

And the tls.crt:  
Certificate:  
Data:  
Version: 3 (0x2)  
Serial Number:  
6e:75:ca:63:fd:1b:11:e6:0b:aa:33:9a:73:b9:cb:bd  
Signature Algorithm: sha256WithRSAEncryption  
Issuer: CN = cs-ca-certificate  
Validity  
Not Before: Dec 19 21:38:47 2021 GMT  
Not After : Mar 19 21:38:47 2022 GMT  
Subject: CN = fdb-internal-tls-certificate  
Subject Public Key Info:  
Public Key Algorithm: rsaEncryption  
RSA Public-Key: (2048 bit)

---

<div class="post-metadata">

**Author:** ![john\_brownlee](https://sea1.discourse-cdn.com/foundationdb/user_avatar/forums.foundationdb.org/john_brownlee/32/22_2.png) [@john\_brownlee](https://forums.foundationdb.org/u/john_brownlee)\
**Post date:** [February 22, 2022, 4:44pm UTC](https://forums.foundationdb.org/t/enabling-peervertificationrules-with-self-signed-certificate-on-ocp-k8s/3187/4 "2022-02-22T16:44:20Z")

</div>

That may not be supported by the sidecar process’s TLS verification rules. I think it’s the default in FDB, and the behavior it’s describing is the default in the sidecar, so you shouldn’t need to pass it explicitly.

---

<div class="post-metadata">

**Author:** ![tangerine](https://sea1.discourse-cdn.com/foundationdb/user_avatar/forums.foundationdb.org/tangerine/32/1084_2.png) [@tangerine](https://forums.foundationdb.org/u/tangerine)\
**Post date:** [February 22, 2022, 9:07pm UTC](https://forums.foundationdb.org/t/enabling-peervertificationrules-with-self-signed-certificate-on-ocp-k8s/3187/5 "2022-02-22T21:07:51Z")

</div>

So, you are saying that, don’t set the rules on the sidecar, just only on the main?

---

<div class="post-metadata">

**Author:** ![john\_brownlee](https://sea1.discourse-cdn.com/foundationdb/user_avatar/forums.foundationdb.org/john_brownlee/32/22_2.png) [@john\_brownlee](https://forums.foundationdb.org/u/john_brownlee)\
**Post date:** [February 22, 2022, 9:34pm UTC](https://forums.foundationdb.org/t/enabling-peervertificationrules-with-self-signed-certificate-on-ocp-k8s/3187/6 "2022-02-22T21:34:52Z")

</div>

If the only rule you have is `Check.Valid=1`, then you shouldn’t need to set it anywhere.

---

<div class="post-metadata">

**Author:** ![tangerine](https://sea1.discourse-cdn.com/foundationdb/user_avatar/forums.foundationdb.org/tangerine/32/1084_2.png) [@tangerine](https://forums.foundationdb.org/u/tangerine)\
**Post date:** [February 22, 2022, 9:51pm UTC](https://forums.foundationdb.org/t/enabling-peervertificationrules-with-self-signed-certificate-on-ocp-k8s/3187/7 "2022-02-22T21:51:43Z")

</div>

Well, that’s not the only rule. That one there is just for testing if I can enable the rule at all.  
Here is a more realistic rule:  
peerVerificationRules: “S.CN=\*.somedomain.xyz.test.com”

---

<div class="post-metadata">

**Author:** ![john\_brownlee](https://sea1.discourse-cdn.com/foundationdb/user_avatar/forums.foundationdb.org/john_brownlee/32/22_2.png) [@john\_brownlee](https://forums.foundationdb.org/u/john_brownlee)\
**Post date:** [February 23, 2022, 4:04pm UTC](https://forums.foundationdb.org/t/enabling-peervertificationrules-with-self-signed-certificate-on-ocp-k8s/3187/8 "2022-02-23T16:04:54Z")

</div>

In general, you should set peer verification rules on both containers if you need to restrict access to both processes. A rule like the one you listed should be accepted by both FoundationDB and the sidecar. I would consider it a bug that the sidecar doesn’t accept `Check.Valid=1` as a rule, and if that’s what’s causing the behavior you’re seeing then it suggests the logging and messaging could be clearer as well.

---

<div class="post-metadata">

**Author:** ![tangerine](https://sea1.discourse-cdn.com/foundationdb/user_avatar/forums.foundationdb.org/tangerine/32/1084_2.png) [@tangerine](https://forums.foundationdb.org/u/tangerine)\
**Post date:** [February 23, 2022, 5:00pm UTC](https://forums.foundationdb.org/t/enabling-peervertificationrules-with-self-signed-certificate-on-ocp-k8s/3187/9 "2022-02-23T17:00:31Z")

</div>

Hi John,  
At least for the 6.2.29 version, I get rid of the peer rule on the sidecar and the DB can comes up with TLS and peer rule on the main. The question I have is, I also have disable\_sidecar\_tls\_check set to 1, would that be the cause of this issue?
