Bug 1038004 - Document recent ssl support changes - hostname and server certificate validation
Summary: Document recent ssl support changes - hostname and server certificate validation
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Enterprise MRG
Classification: Red Hat
Component: Messaging_Installation_and_Configuration_Guide
Version: Development
Hardware: Unspecified
OS: Unspecified
unspecified
high
Target Milestone: 3.0
: ---
Assignee: Jared MORGAN
QA Contact: Petr Matousek
URL:
Whiteboard:
Depends On: 965441
Blocks: 885167 885173
TreeView+ depends on / blocked
 
Reported: 2013-12-04 09:16 UTC by Petr Matousek
Modified: 2015-08-10 01:23 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of: 965441
Environment:
Last Closed: 2015-01-22 15:27:47 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Comment 1 Petr Matousek 2013-12-04 09:20:22 UTC
This content is also valid for mrg-m-3.0.0 and shall be incorporated to the 3.0 MCIG.

Comment 3 Petr Matousek 2014-05-05 11:38:56 UTC
(In reply to Joshua Wulf from comment #2)
> Change also applied in MRG 3:
> 
> http://deathstar1.usersys.redhat.com:3000/builds/18173-
> Messaging_Installation_and_Configuration_Guide/index.
> html#Configure_SASL_using_a_Local_Password_File

The above mentioned chapter is not related to the bug description. These bug is related to SSL python client setup. I would expect a new chapter "Enable SSL in Python Clients" (like in MCIG for MRG 2.x). The description is still missing in the 3.x documentation.

-> ASSIGNED

Comment 5 Petr Matousek 2014-05-06 11:27:57 UTC
The content looks good now, only one issue here:

As mentioned in the bug description above (point 2.), the following sentence is no longer valid:
"Server authentication is not supported."

I'd suggest the following change:

<<<
"The Python client has some limitations in SSL functionality.

Server authentication is not supported. Python clients support authentication with SSL, with some caveats:

The Python clients ..."

>>>
"The Python client has some limitations in SSL functionality:

Server authentication must be demanded, client name must be explicitly provided when using EXTERNAL SASL mechanism for authentication.

The Python clients ..."

Comment 7 Petr Matousek 2014-05-15 08:15:39 UTC
Thakns for the update. Content approved.

-> VERIFIED


Note You need to log in before you can comment on or make changes to this bug.