Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  • Manage Certificates for Projects

  • Upload SSL Certificate

Image Modified

3.3 Add Load balancer with SSL

...

Certificate

The protocol MUST be "SSL"



Choose a certificate


3.4

...

Manage SSL certificate of Load balancer


If protocol is not SSL, click "Edit", change protocol to "SSL"

...

OR remove the current certificate



Please note: when change protocol from SSL to other protocols, the assigned SSL certificate is automatically removed.


3.5 Haproxy configuration for SSL certificate in Virtual Router

...

Code Block
listen 10_0_57_11-443
        	bind 10.0.57.11:443 ssl crt /etc/cloudstack/ssl/cloudstack/10_0_57_11-443.pem alpn h2,http/1.1 ssl-min-ver TLSv1.2 no-tls-tickets ciphers ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256 ciphersuites TLS_AES_128256_GCM_SHA256SHA384:TLS_AES_256128_GCM_SHA384
        SHA256:TLS_CHACHA20_POLY1305_SHA256
	http-request add-header X-Forwarded-Proto https
        	mode http
        	option httpclose
        	balance roundrobin
        	server 10_0_57_11-443_0 10.1.1.149:80 check ssl-min-ver TLSv1.2 no-tls-tickets ciphers ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256 ciphersuites TLS_AES_128256_GCM_SHA256SHA384:TLS_AES_256128_GCM_SHA384
_SHA256:TLS_CHACHA20_POLY1305_SHA256    


4. Test plan


This is automated by test/integration/smoke/test_ssl_offloading.py

...

# 1. Create isolated network and vm instance
# 2. create LB with port 80 -> 80, verify the website (should get expected content)
# 3. create LB with port 443 -> 80, verify the website (should not work)
# 4. add cert to LB with port 443
# 5. verify the website (should get expected content)
# 6. remove cert from LB with port 443
# 7. delete SSL certificate


5. References


Mozilla SSL Configuration Generator: https://ssl-config.mozilla.org/#server=haproxy&version=2.6.12&config=intermediate&openssl=3.0.16&hsts=false&guideline=5.4