Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up

2013-11-26 Thread Evgeny Fedoruk
pment Mailing List (not for usage questions); stephen.g...@guardian.co.uk Subject: Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up Yes. The following can be added 1. Certificate Chain as you already observed 2. Backend certificates for trust, basically CA certs. These certifi

Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up

2013-11-20 Thread Vijay Venkatachalam
age- > From: Samuel Bercovici [mailto:samu...@radware.com] > Sent: Wednesday, November 20, 2013 5:40 PM > To: OpenStack Development Mailing List (not for usage questions); > stephen.g...@guardian.co.uk; Vijay Venkatachalam > Subject: RE: [openstack-dev] [Neutron][LBaaS] SSL Terminatio

Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up

2013-11-20 Thread Samuel Bercovici
questions) Subject: Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up > -Original Message- > From: Stephen Gran [mailto:stephen.g...@guardian.co.uk] > Sent: Wednesday, November 20, 2013 3:01 PM > To: OpenStack Development Mailing List (not for usage questions) &

Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up

2013-11-20 Thread Vijay Venkatachalam
> -Original Message- > From: Stephen Gran [mailto:stephen.g...@guardian.co.uk] > Sent: Wednesday, November 20, 2013 3:01 PM > To: OpenStack Development Mailing List (not for usage questions) > Subject: Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up >

Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up

2013-11-20 Thread Vijay Venkatachalam
ey > felt that this is not secured enough. > > Do you say, that you are OK with storing SSL certificates in the OpenStack > database? > > > > -Sam. > > > > > > -Original Message- > > From: Stephen Gran [mailto:stephen.g...@theguardian.com] >

Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up

2013-11-20 Thread Stephen Gran
Hi, On Wed, 2013-11-20 at 08:24 +, Samuel Bercovici wrote: > Hi, > > > > Evgeny has outlined the wiki for the proposed change at: > https://wiki.openstack.org/wiki/Neutron/LBaaS/SSL which is in line > with what was discussed during the summit. > > The > https://docs.google.com/document/d/

Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up

2013-11-20 Thread Stephen Gran
.@theguardian.com] > Sent: Wednesday, November 20, 2013 10:15 AM > To: openstack-dev@lists.openstack.org > Subject: Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up > > On 19/11/13 16:33, Clint Byrum wrote: > > Excerpts from Vijay Venkatacha

Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up

2013-11-20 Thread Samuel Bercovici
. -Original Message- From: Stephen Gran [mailto:stephen.g...@theguardian.com] Sent: Wednesday, November 20, 2013 10:15 AM To: openstack-dev@lists.openstack.org Subject: Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up On 19/11/13 16:33, Clint Byrum wrote: > Excerpts from Vi

Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up

2013-11-20 Thread Samuel Bercovici
...@citrix.com] Sent: Wednesday, November 20, 2013 8:06 AM To: Eugene Nikanorov Cc: Samuel Bercovici; Avishay Balderman; openstack-dev@lists.openstack.org Subject: RE: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up Hi Eugene, The proposal is simple, create a separate resource

Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up

2013-11-20 Thread Stephen Gran
On 19/11/13 16:33, Clint Byrum wrote: Excerpts from Vijay Venkatachalam's message of 2013-11-19 05:48:43 -0800: Hi Sam, Eugene,& Avishay, etal, Today I spent some time to create a write-up for SSL Termination not exactly design doc. Please share your comments! https://docs.g

Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up

2013-11-19 Thread Andrew Hutchings
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 19/11/13 16:33, Clint Byrum wrote: > Excerpts from Vijay Venkatachalam's message of 2013-11-19 05:48:43 > -0800: >> Hi Sam, Eugene, & Avishay, etal, >> >> Today I spent some time to create a write-up for SSL Termination >> not exactly design doc. P

Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up

2013-11-19 Thread Vijay Venkatachalam
Bercovici; Avishay Balderman; openstack-dev@lists.openstack.org Subject: Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up Hi Vijay, Thanks for working on this. As was discussed at the summit, immediate solution seems to be passing certificates via transient fields in Vip object

Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up

2013-11-19 Thread Eugene Nikanorov
Hi Vijay, Thanks for working on this. As was discussed at the summit, immediate solution seems to be passing certificates via transient fields in Vip object, which will avoid the need for certificate management (incl. storing them). If certificate management is concerned then I agree that it needs

Re: [openstack-dev] [Neutron][LBaaS] SSL Termination write-up

2013-11-19 Thread Clint Byrum
Excerpts from Vijay Venkatachalam's message of 2013-11-19 05:48:43 -0800: > Hi Sam, Eugene, & Avishay, etal, > > Today I spent some time to create a write-up for SSL > Termination not exactly design doc. Please share your comments! > > https://docs.google.com/document/d/1tFOrIa10

[openstack-dev] [Neutron][LBaaS] SSL Termination write-up

2013-11-19 Thread Vijay Venkatachalam
Hi Sam, Eugene, & Avishay, etal, Today I spent some time to create a write-up for SSL Termination not exactly design doc. Please share your comments! https://docs.google.com/document/d/1tFOrIa10lKr0xQyLVGsVfXr29NQBq2nYTvMkMJ_inbo/edit Would like comments/discussion especially on