Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  • Manage Certificates for Projects

  • Upload SSL Certificate

Image Modified

3.3 Add Load balancer with SSL

...

Certificate

The protocol MUST be "SSL"



Choose a certificate


3.4

...

Manage SSL certificate of Load balancer


If protocol is not SSL, click "Edit", change protocol to "SSL"

...

OR remove the current certificate



Please note: when change protocol from SSL to other protocols, the assigned SSL certificate is automatically removed.


3.5 Haproxy configuration for SSL certificate in Virtual Router

The 


The SSL certificate and private key are saved in a pem file



Code Block
root@r-22-VM:~# cat /etc/cloudstack/ssl/10_0_57_11-443.pem 
-----BEGIN CERTIFICATE-----
// server certificate
-----END CERTIFICATE-----

-----BEGIN CERTIFICATE-----
// chain 1
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
// chain 2
-----END CERTIFICATE-----

-----BEGIN PRIVATE KEY-----
// private key
-----END PRIVATE KEY-----
   


HAproxy configuration for the load balancer


Code Block
listen 10_0_57_11-443
	bind 10.0.57.11:443 ssl crt /etc/cloudstack/ssl/10_0_57_11-443.pem alpn h2,http/1.1 ssl-min-ver TLSv1.2 no-tls-tickets ciphers ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256 ciphersuites TLS_AES_256_GCM_SHA384:TLS_AES_128_GCM_SHA256:TLS_CHACHA20_POLY1305_SHA256
	http-request add-header X-Forwarded-Proto https
	mode http
	option httpclose
	balance roundrobin
	server 10_0_57_11-443_0 10.1.1.149:80 check ssl-min-ver TLSv1.2 no-tls-tickets ciphers ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256 ciphersuites TLS_AES_256_GCM_SHA384:TLS_AES_128_GCM_SHA256:TLS_CHACHA20_POLY1305_SHA256    
Code Block
example of haproxy.cfg



4. Test plan


This is automated by test/integration/smoke/test_ssl_offloading.py

...

# 1. Create isolated network and vm instance
# 2. create LB with port 80 -> 80, verify the website (should get expected content)
# 3. create LB with port 443 -> 80, verify the website (should not work)
# 4. add cert to LB with port 443
# 5. verify the website (should get expected content)
# 6. remove cert from LB with port 443
# 7. delete SSL certificate


5. References


Mozilla SSL Configuration Generator: https://ssl-config.mozilla.org/#server=haproxy&version=2.6.12&config=intermediate&openssl=3.0.16&hsts=false&guideline=5.4