Return-Path: X-Original-To: apmail-cloudstack-users-archive@www.apache.org Delivered-To: apmail-cloudstack-users-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 80E14110AF for ; Fri, 28 Mar 2014 16:33:06 +0000 (UTC) Received: (qmail 97391 invoked by uid 500); 28 Mar 2014 16:33:05 -0000 Delivered-To: apmail-cloudstack-users-archive@cloudstack.apache.org Received: (qmail 96481 invoked by uid 500); 28 Mar 2014 16:33:04 -0000 Mailing-List: contact users-help@cloudstack.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: users@cloudstack.apache.org Delivered-To: mailing list users@cloudstack.apache.org Received: (qmail 96445 invoked by uid 99); 28 Mar 2014 16:33:02 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 28 Mar 2014 16:33:02 +0000 X-ASF-Spam-Status: No, hits=-0.0 required=5.0 tests=SPF_PASS X-Spam-Check-By: apache.org Received-SPF: pass (athena.apache.org: domain of stevenliang@yesup.com designates 199.21.148.188 as permitted sender) Received: from [199.21.148.188] (HELO smtp.yesup.com) (199.21.148.188) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 28 Mar 2014 16:32:56 +0000 Message-ID: <5335A424.10105@yesup.com> Date: Fri, 28 Mar 2014 12:32:36 -0400 From: stevenliang User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.3.0 MIME-Version: 1.0 To: users@cloudstack.apache.org Subject: Re: [ANNOUNCE] Realhostip Service is Being Retired References: In-Reply-To: Content-Type: text/plain; charset=windows-1252; format=flowed Content-Transfer-Encoding: 8bit X-Virus-Checked: Checked by ClamAV on apache.org Hi John, How configure load balancer to point to console proxy? You means hardware load balancer or cs software? Can you also give a link? Thank you. Steven On 25/03/14 10:54 AM, John Kinsella wrote: > (Sorry folks - resend, with links at bottom) > Realhostip Service is Being Retired > > > Recently the Apache CloudStack PMC was informed that the realhostip.com Dynamic DNS service that CloudStack currently uses as part of the console proxy will be disbanded this summer. The realhostip service will be shut down June 30th, 2014, meaning users have approximately 3 months to mitigate this. > > Prior to version 4.3, CloudStack used the realhostip.com service by default. With the release of CloudStack version 4.3 the default communication method with the console proxy is plaintext HTTP. > > Who is Affected > > CloudStack installations prior to version 4.3 that have not been reconfigured to use a DNS domain other than realhostip.com for Console Proxy or Secondary Storage must make changes to continue functioning past June 30th, 2014. > > Steps You Need to Take > > If you meet the criteria above, there are several options to prepare for realhostip retirement: > > � Set up wildcard SSL certificate and DNS entries: This method is already well supported within prior versions of CloudStack. > � Upgrade to CloudStack 4.3 and disable SSL: This is only recommended for development installations, or private clouds that contain no information of importance. > � Upgrade to CloudStack 4.3, set up static SSL certificate and configure load balancer to point to the correct IP address: While this allows an administrator to skip setting up the DNS entries from the previous option, it is a more advanced option as CloudStack 4.3 does not support automatic load balancer configuration for the Console Proxy. It is hoped this functionality will be available in future releases. > For instructions on how to set up SSL encryption for use with CloudStack console proxy, please read the console proxy section of the CloudStack administration guide[1]. > > Additionally, if you will be using an SSL vendor who requires an intermediate CA chain to be installed for proper SSL validation by web browsers, detailed instructions for configuring the intermediate CA chain in CloudStack can be found at [2]. > > The Apache CloudStack security team does not recommend running a production cloud with either the realhostip.com SSL certificate, or with no SSL encryption at all. > > 1: http://docs.cloudstack.apache.org/projects/cloudstack-administration/en/latest/systemvm.html#console-proxy > 2: http://www.chipchilders.com/blog/2013/1/2/undocumented-feature-using-certificate-chains-in-cloudstack.html >