Skip to content

Commit 059a152

Browse files
authored
customcertificates: update notes (#603)
* customcertificates: update notes Signed-off-by: Abhishek Kumar <abhishek.mrt22@gmail.com> * changes Signed-off-by: Abhishek Kumar <abhishek.mrt22@gmail.com> --------- Signed-off-by: Abhishek Kumar <abhishek.mrt22@gmail.com>
1 parent b323e7d commit 059a152

2 files changed

Lines changed: 87 additions & 23 deletions

File tree

44.5 KB
Loading

‎source/adminguide/systemvm.rst‎

Lines changed: 87 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -382,40 +382,104 @@ The Management Server generates URLs of the form
382382
The new console requests will be served with the new DNS domain name,
383383
certificate, and key.
384384

385-
Uploading ROOT CA and Intermediate CA
386-
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
387-
If you need to upload custom certificate with ROOT CA and intermediate CA, you can find more details here:
385+
Uploading Certificates
386+
~~~~~~~~~~~~~~~~~~~~~~
387+
388+
.. |ssl-certificates.png| image:: /_static/images/ssl-certificates.png
389+
390+
Custom certificates for system VMs (SSVM and CPVM) can be uploaded using
391+
UI or API.
392+
393+
To upload custom certificates following details will be needed:
394+
395+
- ROOT CA certificate
396+
- Intermediate CA certificate(s) (if any)
397+
- Site or server certificate
398+
- Private key (in PKCS8 format)
399+
- Domain name suffix
400+
401+
To upload custom certificates using UI, go to Infrastructure -> SSL
402+
Certificates around the top of the summary view. This will open up the
403+
following form.
404+
405+
|ssl-certificates.png|
406+
407+
Root Certificate, Server Certificate, PKCS#8 private certificate can be
408+
added in the straightforward way.
409+
If there are Intermediate CA certificate(s), then add them one by one
410+
using the `Add intermediate certificate` button.
411+
For DNS domain suffix, you may use a wildcard domain name like
412+
`*.yourdomain.com`.
413+
Clicking on Submit will add certificate entries in the database,
414+
one for ROOT certificate, as many Intermediate certificates as added and one for
415+
server + private certificate.
416+
417+
418+
This can also be achieved using the API `uploadCustomCertificate`. Example
419+
API calls:
420+
421+
.. code::
422+
423+
uploadCustomCertificate id=1 name='Root' certificate='-----BEGIN CERTIFICATE-----...-----END CERTIFICATE-----' domainsuffix='*.yourdomain.com'
424+
uploadCustomCertificate id=2 name='Intermediate1' certificate='-----BEGIN CERTIFICATE-----...-----END CERTIFICATE-----' domainsuffix='*.yourdomain.com'
425+
uploadCustomCertificate id=3 certificate='-----BEGIN CERTIFICATE-----...-----END CERTIFICATE-----' privatekey='-----BEGIN PRIVATE KEY-----...-----END PRIVATE KEY-----' domainsuffix='*.yourdomain.com'
426+
427+
Note: We do not need to provide a name for the server certificate entry, as
428+
it will auto-generate a name since the privatekey is provided.
429+
If there are multiple Intermediate certificates, then multiple API calls will
430+
be needed to upload them one by one.
431+
Also, the first two API calls for Root and Intermediate certificates can be
432+
combined in a single call by using a certificate value which consists of both
433+
Root and Intermediate certificates.
434+
435+
After successfully uploading custom certificates, CloudStack will attempt to
436+
restart all SSVMs and CPVMs. If not restarted then it can be done manually.
437+
438+
More details regarding custom certificates can be found here:
388439
https://cwiki.apache.org/confluence/display/CLOUDSTACK/Procedure+to+Replace+realhostip.com+with+Your+Own+Domain+Name
389440

390441
IMPORTANT NOTES:
391442

392-
In order to avoid errors and problems while uploading custom certificates, please check following:
393-
394-
1. While doing URL encoding of ROOT CA and any Intermediate CA, be sure that the plus signs ("+") inside certificates
395-
are not replaced by space (" "), because some URL/string encoding tools tend to do that.
443+
In order to avoid errors and problems while uploading custom certificates,
444+
please check the following:
396445

397-
2. If you are renewing certificates it might happen you need to upload new ROOT CA and Intermediate CA, together with new Server Certificate and key.
398-
In this case please be sure to use same names for certificates during API upload of certificate, example:
446+
1. When calling the API as an HTTP request and while doing URL encoding of
447+
ROOT CA and any Intermediate CA, be sure that the plus signs ("+") inside
448+
certificates are not replaced by space (" "), because some URL/string
449+
encoding tools tend to do that.
399450

400-
http://123.123.123.123:8080/client/api?command=uploadCustomCertificate&...&name=root1...
401-
http://123.123.123.123:8080/client/api?command=uploadCustomCertificate&...&name=intermed1...
451+
2. If you are renewing certificates, you may need to upload new ROOT CA and
452+
Intermediate CA, together with new Server Certificate and key.
453+
In this case, please be sure to use the same names for certificates during
454+
API upload of the certificate, for example:
402455

403-
Here names are "root1" and "intermed1".
404-
If you used other names previously, please check the cloud.keystore table to obtain used names.
456+
.. code::
405457
406-
If you still have problems and following errors in management.log while destroying CPVM:
458+
http://123.123.123.123:8080/client/api?command=uploadCustomCertificate&...&name=root1...
459+
http://123.123.123.123:8080/client/api?command=uploadCustomCertificate&...&name=intermed1...
407460
408-
- Unable to build keystore for CPVMCertificate due to CertificateException
409-
- Cold not find and construct a valid SSL certificate
461+
Here the names are "root1" and "intermed1".
462+
If you used other names previously, please check the cloud.keystore table
463+
to obtain the used names.
410464

411-
that means that still some of the Root/intermediate/server certificates or the key is not in a good format, or incorrectly encoded or multiply Root CA/Intermediate CA present in database by mistake.
465+
If you still have problems and see the following errors in
466+
management-server.log while starting CPVM:
412467

413-
Other way to renew Certificates (Root,Intermediates,Server certificates and key) - although not recommended
414-
unless you fill comfortable - is to directly edit the database,
415-
while still respect the main requirement that the private key is PKCS8 encoded, while Root CA, Intermediate and Server certificates
416-
are still in default PEM format (no URL encoding needed here).
417-
After editing the database, please restart management server, and destroy SSVM and CPVM after that,
418-
so the new SSVM and CPVM with new certificates are created.
468+
- Unable to build keystore for CPVMCertificate due to CertificateException
469+
- Could not find and construct a valid SSL certificate
470+
471+
This means that some of the Root/Intermediate/Server certificates or the key
472+
is not in a good format, or is incorrectly encoded, or multiple Root
473+
CA/Intermediate CA entries are present in the database by mistake.
474+
475+
Another way to renew certificates (Root, Intermediates, Server certificates
476+
and key) - although not recommended unless you feel comfortable - is to
477+
directly edit the database, while still respecting the main requirement that
478+
the private key is PKCS8 encoded, while Root CA, Intermediate and Server
479+
certificates are in the default PEM format (no URL encoding needed here).
480+
After editing the database, please restart the management server, and destroy
481+
the SSVM and CPVM after that, so that new SSVM and CPVM instances with new
482+
certificates are created.
419483

420484
Load-balancing Console Proxies / Secondary Storage VMs
421485
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

0 commit comments

Comments
 (0)