Bug 961511

Summary: [RFE] Support full iSCSI authentication
Product: [Retired] oVirt Reporter: Dax Kelson <dkelson>
Component: ovirt-engine-webadminAssignee: Allon Mureinik <amureini>
Status: CLOSED WONTFIX QA Contact: bugs <bugs>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: unspecifiedCC: acathrow, amureini, ecohen, iheim, mgoldboi, nsoffer
Target Milestone: ---Keywords: Improvement
Target Release: 3.5.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: storage
Fixed In Version: Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-06-16 15:39:54 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: Storage RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Dax Kelson 2013-05-09 19:07:11 UTC
Description of problem:

Best practice and secure iSCSI deployment uses mutual authentication with separate username and passwords for each LUN that is different from the DISCOVERY credentials.

In other words, ovirt needs the following UI and support

------DISCOVERY phase------

Optional Outbound credentials:

username:
password:

Optional inbound (mutual) credentials:

username:
password:


-------Then for EACH LUN, allow credentials to be input --------

Optional  Outbound credentials:

username:
password:

Optional inbound (mutual) credentials:

username:
password:

------------------------------------------------------------------

RHEL6 Anaconda gets this treatment of iSCSI authentication correct (it was broken similar to ovirt in RHEL5).

Comment 1 Itamar Heim 2014-06-16 15:39:54 UTC
Closing old bugs. If this issue is still relevant/important in current version, please re-open the bug.