Hi Sam, Eugene, & Avishay, etal,
Today I spent some time to create a write-up for SSL
Termination not exactly design doc. Please share your comments!
https://docs.google.com/document/d/1tFOrIa10lKr0xQyLVGsVfXr29NQBq2nYTvMkMJ_inbo/edit
Would like comments/discussion especially on the following note:
SSL Termination requires certificate management. The ideal way is to handle
this via an independent IAM service. This would take time to implement so the
thought was to add the certificate details in VIP resource and send them
directly to device. Basically don't store the certificate key in the DB there
by avoiding security concerns of maintaining certificates in controller.
I would expect the certificates to become an independent resource in future
thereby causing backward compatibility issues.
Any ideas how to achieve this?
My thought was to have independent certificate resource with VIP uuid as one of
the properties. VIP is already created and will help to identify the
driver/device. The VIP property can be depreciated in the long term.
Thanks,
Vijay V.
_______________________________________________
OpenStack-dev mailing list
[email protected]
http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev