[1.16.2, 1.15.6, 1.14.10] Vault CA with Vault namespace config will prevent CA initialization #19051
Labels
theme/certificates
Related to creating, distributing, and rotating certificates in Consul
theme/consul-vault
Relating to Consul & Vault interactions
type/bug
Feature does not function as expected
This impacts Consul users using Vault Enterprise's namespace for Vault CA configuration (docs).
Overview of the Issue
Consul versions 1.16.2, 1.15.6, and 1.14.10 suffer a regression introduced by #18773 where empty RootPKINamespace or IntermediatePKINamespace do not fall back to the global Namespace.
This means you may see error logs such as:
Workaround
The above issue can be mitigated by setting all 3 namespace fields to the same value:
The text was updated successfully, but these errors were encountered: