Skip to content

cephadm: truncate X.509 Common Name to 64 chars in generate_cert - #71407

Open
joshjan20 wants to merge 1 commit into
ceph:mainfrom
joshjan20:fix-cephadm-cn-length-limit
Open

cephadm: truncate X.509 Common Name to 64 chars in generate_cert#71407
joshjan20 wants to merge 1 commit into
ceph:mainfrom
joshjan20:fix-cephadm-cn-length-limit

Conversation

@joshjan20

Copy link
Copy Markdown

The Common Name (CN) field in the certificate subject is limited to 64 characters per RFC 5280. generate_cert() previously passed the raw address/hostname directly as the CN with no length check. On cloud providers with long auto-assigned FQDNs (e.g. Google Cloud Platform, which embeds the project ID into every VM hostname), this can easily exceed 64 characters, causing certificate signing to fail with an opaque low-level error:

asn1 encoding routines: ... string too long

This surfaces to the user as an unexplained failure to deploy services that require a generated certificate (e.g. Grafana), with no indication that hostname length is the actual cause.

TLS hostname verification relies on the SAN (Subject Alternative Name) list, not the CN. The full, untruncated hostname is already present in the SAN, added separately in this same method. Truncating only the CN when it exceeds 64 characters therefore has no effect on certificate validity or hostname verification; it only avoids the signing failure.

The fix truncates the CN to 64 characters when needed. This does not affect certificate validity or TLS hostname verification, which relies on the SAN (Subject Alternative Name) list, not the CN; the full, untruncated hostname remains present in the SAN, unmodified.

Adds regression tests covering: the long-FQDN case no longer raising, the full FQDN remaining present in the SAN after truncation, short hostnames being left unmodified, and truncation landing at exactly 64 characters when it does occur.

Includes 4 regression tests, verified passing locally in a standalone environment (see commit message for details); full test suite integration will run via CI once labeled.

Contribution Guidelines

  • To sign and title your commits, please refer to Submitting Patches to Ceph.

  • If you are submitting a fix for a stable branch (e.g. "quincy"), please refer to Submitting Patches to Ceph - Backports for the proper workflow.

  • When filling out the below checklist, you may click boxes directly in the GitHub web UI. When entering or editing the entire PR message in the GitHub web UI editor, you may also select a checklist item by adding an x between the brackets: [x]. Spaces and capitalization matter when checking off items this way.

Checklist

  • Tracker (select at least one)
    • References tracker ticket
    • Very recent bug; references commit where it was introduced
    • New feature (ticket optional)
    • Doc update (no ticket needed)
    • Code cleanup (no ticket needed)
  • Component impact
    • Affects Dashboard, opened tracker ticket
    • Affects Orchestrator, opened tracker ticket
    • No impact that needs to be tracked
  • Documentation (select at least one)
    • Updates relevant documentation
    • No doc update is appropriate
  • Tests (select at least one)
Show available Jenkins commands

You must only issue one Jenkins command per-comment. Jenkins does not understand
comments with more than one command.

The Common Name (CN) field in the certificate subject is limited to
64 characters per RFC 5280. generate_cert() previously passed the raw
address/hostname directly as the CN with no length check. On cloud
providers with long auto-assigned FQDNs (e.g. Google Cloud Platform,
which embeds the project ID into every VM hostname), this can easily
exceed 64 characters, causing certificate signing to fail with an
opaque low-level error:

  asn1 encoding routines: ... string too long

This surfaces to the user as an unexplained failure to deploy
services that require a generated certificate (e.g. Grafana), with
no indication that hostname length is the actual cause.

TLS hostname verification relies on the SAN (Subject Alternative
Name) list, not the CN. The full, untruncated hostname is already
present in the SAN, added separately in this same method. Truncating
only the CN when it exceeds 64 characters therefore has no effect on
certificate validity or hostname verification; it only avoids the
signing failure.

Adds regression tests covering: the long-FQDN case no longer raising,
the full FQDN remaining present in the SAN after truncation, short
hostnames being left unmodified, and truncation landing at exactly
64 characters when it does occur.

Signed-off-by: joshjan20 <joshjan20@gmail.com>
@joshjan20
joshjan20 requested a review from a team as a code owner August 28, 2026 21:29
@github-actions

Copy link
Copy Markdown

Thank you for your contribution. Since you are not yet a member of the Ceph organization with write permissions on ceph/ceph.git, our CI will not automatically run. Any member of the Ceph organization may label this PR ci-approved to allow Jenkins CI jobs to run.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant