cloudstack-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "ASF subversion and git services (JIRA)" <>
Subject [jira] [Commented] (CLOUDSTACK-5296) Add certificate chain support for NS
Date Thu, 05 Dec 2013 10:07:35 GMT


ASF subversion and git services commented on CLOUDSTACK-5296:

Commit ee7380ace2014f8839417fd79e0a52cf9a0f02cd in branch refs/heads/master from [~sahmed]
[;h=ee7380a ]

CLOUDSTACK-5296: Add certificate chain support for netscaler

This patch adds support for trust chains in the netscaler.

I initially planned on using the 10.1 API's "bundle" feature but during
my testing I found that was not working. So I am doing the chain linking
myself. Also NS can have only one entity of a certificate ie lets say
two different users try to add the same certificate on the netscaler
only one of them will go through. The other one says resouce already
exists even though they have different files.

This can be a problem in trust chains where the chain can be shared
between multiple accounts/certificates. So, I am using the figerprint as
an identifier of a certificate and making sure that we delete it only
when no one references it.

> Add certificate chain support for NS
> ------------------------------------
>                 Key: CLOUDSTACK-5296
>                 URL:
>             Project: CloudStack
>          Issue Type: Bug
>      Security Level: Public(Anyone can view this level - this is the default.) 
>          Components: Network Devices
>    Affects Versions: 4.3.0
>            Reporter: Syed Ahmed
>             Fix For: 4.3.0
> Right now the SSL termination functionality for Netscaler does not support trust chains.

> In netscaler if you have two certificates sharing the same trust chain, you cannot create
two different entities for intermediate chains. ie no certificate can be same. 
> This should be taken care while deleting the certs too. As the chain in one may be shared
by the other. 

This message was sent by Atlassian JIRA

View raw message