Bug 1444893

Summary: [RFE] OVN provider TLS encryption support for authentication and clients traffic
Product: [oVirt] ovirt-provider-ovn Reporter: Mor <mkalfon>
Component: providerAssignee: Marcin Mirecki <mmirecki>
Status: CLOSED CURRENTRELEASE QA Contact: Mor <mkalfon>
Severity: high Docs Contact:
Priority: high    
Version: 1.0.4CC: bugs, danken, lbopf, myakove, ylavi
Target Milestone: ovirt-4.2.0Keywords: FutureFeature
Target Release: ---Flags: rule-engine: ovirt-4.2+
gklein: testing_plan_complete-
ylavi: planning_ack+
danken: devel_ack+
rule-engine: testing_ack+
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: No Doc Update
Doc Text:
undefined
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-12-20 11:28:59 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: Network RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1445172    

Description Mor 2017-04-24 13:46:57 UTC
Description of RFE:

1. OVN provider should support SSL to authenticate provider user requests. Currently in RHV, we use unencrypted HTTP protocol to communicate with the provider.

2. OVN traffic between OVN hosts (controllers) and OVN-central server (OVSDB) should be encrypted using SSL. In 2.7.1 http://openvswitch.org/releases/NEWS-2.7.0 version it is being supported officially by the OVN project.

Additional info:

External BZ opened by Marcin Mirecki: 
https://bugzilla.redhat.com/show_bug.cgi?id=1396143 for OVS/OVN team.

Comment 1 Mor 2017-09-03 08:56:10 UTC
Verified on: 
4.2.0-0.0.master.20170901193740.git7900511.el7.centos

NB-DB and SB-DB are configured by default for SSL.

Comment 2 Sandro Bonazzola 2017-12-20 11:28:59 UTC
This bugzilla is included in oVirt 4.2.0 release, published on Dec 20th 2017.

Since the problem described in this bug report should be
resolved in oVirt 4.2.0 release, published on Dec 20th 2017, it has been closed with a resolution of CURRENT RELEASE.

If the solution does not work for you, please open a new bug report.