Bug 835018
Summary: | Generate separate certificates for spice / display network, update them on display network modification | ||
---|---|---|---|
Product: | [Retired] oVirt | Reporter: | David Jaša <djasa> |
Component: | ovirt-engine-core | Assignee: | Nobody's working on this, feel free to take it <nobody> |
Status: | CLOSED WONTFIX | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | abaron, acathrow, bazulay, cfergeau, desktop-qa-list, dyasny, iheim, mgoldboi, michal.skrivanek, ykaul |
Target Milestone: | --- | Keywords: | FutureFeature |
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
URL: | http://www.ovirt.org/wiki/Features/One_certificate-key_pair_per_NIC | ||
Whiteboard: | infra | ||
Fixed In Version: | Doc Type: | Enhancement | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2013-03-13 17:08:46 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
David Jaša
2012-06-25 09:15:46 UTC
oVirt feature page based on this RFE: https://bugzilla.redhat.com/show_bug.cgi?id=835018 (In reply to comment #1) > oVirt feature page based on this RFE: > https://bugzilla.redhat.com/show_bug.cgi?id=835018 Wrong link? Also, put it in the URL section of the BZ. (In reply to comment #2) > (In reply to comment #1) > > Wrong link? Also, put it in the URL section of the BZ. Yes. Correct link (added to URL too): http://www.ovirt.org/wiki/Features/One_certificate-key_pair_per_NIC michal - thoughts on this? I don't think it can go away. IIUC when connecting through NAT we do not differentiate interfaces, for vdsm it is the same connection as if from internal nw. It may make sense for display nw specificaly, but I'm not sure it's worth the effort when it's already working as it is and we would anyway need it for NAT - e.g. with the new Display Address Override David? It would be cleaner for host subject CN to match display network name/address (or display network override name/address) but since the host subject is correctly reported in the API, the status quo is not that bad. Itamar/Michal, please deprecate the feature page accordingly. |