need to set https_validate_certificates in boto config as well as is_secure

Bug #1130345 reported by Clint Byrum
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack Heat
Fix Released
Medium
Clint Byrum

Bug Description

boto does not, by default, validate https ceritificates on endpoints. I would suggest that Heat make it default to on, but I understand that may complicate issues. Either way, we need a way to specify it in the heat configuration along side is_secure. Heat deployers may also need to turn this off if boto ever does make it default and they want to use self signed certs.

I suggest we make the config option

instance_connection_https_validate_certificates

As this matches the form of is_secure

Changed in heat:
assignee: nobody → Clint Byrum (clint-fewbar)
status: New → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to heat (master)

Fix proposed to branch: master
Review: https://review.openstack.org/22354

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to heat (master)

Reviewed: https://review.openstack.org/22354
Committed: http://github.com/openstack/heat/commit/14358bb9e1bdeb2a1deb3311cd0232ba41f69685
Submitter: Jenkins
Branch: master

commit 14358bb9e1bdeb2a1deb3311cd0232ba41f69685
Author: Clint Byrum <email address hidden>
Date: Tue Feb 19 12:21:07 2013 -0800

    Add config for boto https_validate_certificates

    Boto does not, by default, validate https ceritificates on endpoints. We
    now provide a way to specify it in the heat configuration along side
    is_secure. Heat deployers may also need to turn this off if boto ever
    does make it default and they want to use self signed certs.

    Fixes bug #1130345

    Change-Id: I09b684dd28a8a57c6ce514d1df1e699e7c8b182e

Changed in heat:
status: In Progress → Fix Committed
Steven Hardy (shardy)
Changed in heat:
milestone: none → grizzly-3
importance: Undecided → Medium
Thierry Carrez (ttx)
Changed in heat:
status: Fix Committed → Fix Released
Thierry Carrez (ttx)
Changed in heat:
milestone: grizzly-3 → 2013.1
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.