+++ This bug was initially created as a clone of Bug #1086964, so that the feature could be considered for back-port to OSP 10 +++
Cloned from launchpad blueprint https://blueprints.launchpad.net/nova/+spec/websocket-proxy-to-host-security.
Description:
Currently, while the noVNC and HTML5 SPICE clients can use TLS-encrypted
WebSockets to communicate with Websockify (and authenticate with Nova console
tokens), the encryption and authentication ends there. There are neither
encryption nor authentication between Websockify and the hypervisors'
VNC and SPICE servers.
This blueprint would propose introducing a generic framework for supporting
MITM security for Websockify to use between itself and the compute nodes.
Specification URL (additional information):
None