Back to bug 1384334

Who When What Removed Added
Marius Cornea 2016-10-13 07:24:13 UTC Blocks 1384340
Nathan Kinder 2016-10-21 16:58:32 UTC CC nkinder
Assaf Muller 2016-10-21 17:08:47 UTC Priority unspecified high
Target Release --- 10.0 (Newton)
Link ID OpenStack gerrit 387356
Target Milestone --- rc
Ofer Blaut 2016-10-25 09:31:43 UTC CC oblaut
QA Contact tfreger mcornea
Ihar Hrachyshka 2016-11-02 17:00:20 UTC CC ihrachys
Ihar Hrachyshka 2016-11-02 17:00:48 UTC CC rhos-flags
Flags needinfo?(rhos-flags)
John Schwarz 2016-11-02 17:03:14 UTC CC jschwarz
Nir Yechiel 2016-11-03 08:49:10 UTC Flags needinfo?(rhos-flags)
Nir Yechiel 2016-11-03 08:50:17 UTC Status NEW ON_DEV
Assignee amuller jschwarz
John Schwarz 2016-11-03 11:33:41 UTC Status ON_DEV POST
Jon Schlueter 2016-11-04 15:14:19 UTC CC jschluet
John Schwarz 2016-11-07 12:32:56 UTC Status POST MODIFIED
Fixed In Version openstack-neutron-9.0.0-1.7.el7ost
errata-xmlrpc 2016-11-07 21:48:19 UTC Status MODIFIED ON_QA
Jon Schlueter 2016-11-17 05:14:08 UTC Keywords Triaged
Ihar Hrachyshka 2016-11-28 16:16:18 UTC CC mcornea
Flags needinfo?(mcornea)
Marius Cornea 2016-11-28 16:29:59 UTC Flags needinfo?(mcornea)
John Schwarz 2016-11-28 16:33:02 UTC CC mburns
Flags needinfo?(mburns)
Marius Cornea 2016-11-29 11:53:32 UTC Status ON_QA VERIFIED
Mike Burns 2016-11-29 12:27:31 UTC Flags needinfo?(mburns)
John Schwarz 2016-12-06 06:07:38 UTC Doc Text Cause: When using a proxy (such as 'haproxy' used in OSP-D) between the client and the server, and the client used SSL, the server would ignore this option and won't use SSL when requesting Neutron's endpoints.

Consequence: The wrong protocol will be used.

Fix: A middleware was added that changes the protocol to return 'https' requests.

Result: The correct protocol is now used.
Doc Type If docs needed, set a value Bug Fix
Don Domingo 2016-12-14 02:08:38 UTC CC ddomingo
Doc Text Cause: When using a proxy (such as 'haproxy' used in OSP-D) between the client and the server, and the client used SSL, the server would ignore this option and won't use SSL when requesting Neutron's endpoints.

Consequence: The wrong protocol will be used.

Fix: A middleware was added that changes the protocol to return 'https' requests.

Result: The correct protocol is now used.
This release adds a HTTPProxyToWSGI middleware in front of the OpenStack Networking API to set up a request URL correctly in case a proxy (eg. HAProxy) is used between the client and server. This ensures that when a client uses SSL, the server recognizes this and responds using the correct protocol. Previously, using a proxy made it possible for the server to respond with HTTP (instead of HTTPS) even when a client used SSL.
errata-xmlrpc 2016-12-14 14:11:08 UTC Status VERIFIED RELEASE_PENDING
errata-xmlrpc 2016-12-14 16:18:25 UTC Status RELEASE_PENDING CLOSED
Resolution --- ERRATA
Last Closed 2016-12-14 11:18:25 UTC

Back to bug 1384334