Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1058840 - Issues with secure websockets
Issues with secure websockets
Status: CLOSED WONTFIX
Product: OpenShift Online
Classification: Red Hat
Component: Containers (Show other bugs)
2.x
Unspecified Unspecified
low Severity low
: ---
: ---
Assigned To: Rory Thrasher
libra bugs
: Reopened
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2014-01-28 10:40 EST by Nikhil Mone
Modified: 2017-07-10 11:52 EDT (History)
12 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2017-05-31 14:22:11 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Nikhil Mone 2014-01-28 10:40:31 EST
Description of problem:

For requests made  on port 8443, the proxy server is always using the *.rhcloud.com SSL certificate, even for apps which have custom SSL certs


Version-Release number of selected component (if applicable):


How reproducible:

# curl -I -N -H "Connection: Upgrade" -H "Upgrade: websocket" -H "Host: www.abc.com" https://www.abc.com:8443
curl: (51) Unable to communicate securely with peer: requested domain name does not match the server's certificate.


Steps to Reproduce:
1.
2.
3.

Actual results:

the proxy server is always using the *.rhcloud.com SSL certificate

Expected results:

It should use the custom certificate associated with app.

Additional info:
Comment 1 Mrunal Patel 2014-01-29 20:26:32 EST
This hasn't been implemented yet. I have added a card to track this feature request.

https://trello.com/c/YXoKyA8d/399-add-custom-ssl-support-for-node-web-proxy
Comment 4 Josep 'Pep' Turro Mauri 2014-12-03 06:37:52 EST
(In reply to Kenjiro Nakayama from comment #3)
> Looks same with https://bugzilla.redhat.com/show_bug.cgi?id=1160380

Yes. And from that bz, the "new" trello card is here:

https://trello.com/c/EzMdQCQn/571-add-per-app-ssl-certificate-support-to-the-nodejs-websocket-frontend-plugin
Comment 6 Mrunal Patel 2015-12-14 18:16:49 EST
Eric Jones,
I don't see the card either. We need a new card for this as it hasn't been implemented yet.
Comment 14 paulrbr 2017-04-01 19:48:33 EDT
Hello,

I have been wondering why I can't reach my custom domain secured websocket until I found this open bug.

Is there any possibility to fix this on Openshift Online? Do you know if thus will be fixed one day?

Thanks for the help,
Comment 15 Eric Paris 2017-05-31 14:22:11 EDT
We apologize, however, we do not plan to address this report at this time. The majority of our active development is for the v3 version of OpenShift. If you would like for Red Hat to reconsider this decision, please reach out to your support representative. We are very sorry for any inconvenience this may cause.

Note You need to log in before you can comment on or make changes to this bug.