1. Objectives


The SSL termination (SSL offloading) feature was introduced in Apache CloudStack 4.13.

    Bug: https://issues.apache.org/jira/browse/CLOUDSTACK-4821
    FS: https://cwiki.apache.org/confluence/display/CLOUDSTACK/SSL+Termination+Support

However, this feature is only implemented for Citrix Netscaler by commit https://github.com/apache/cloudstack/commit/0076307


This improvement derives from a feature design in Apache CloudStack 4.15:  VR haproxy customization in CloudStack (which is not merged)

2. High Level Design


This improves SSL offloading feature which includes


3. Implementation

This described some details of the implementation

3.1 database change


None.

3.2 UI changes for Certificates management

3.3 Add Load balancer with SSL Certificate

The protocol MUST be "SSL"



Choose a certificate


3.4 Manage SSL certificate of Load balancer


If protocol is not SSL, click "Edit", change protocol to "SSL"



Click "Manage Certificate" to assign a certificate


OR remove the current certificate



Please note: when change protocol from SSL to other protocols, the assigned SSL certificate is automatically removed.


3.5 Haproxy configuration for SSL certificate in Virtual Router


The SSL certificate and private key are saved in a pem file



root@r-22-VM:~# cat /etc/cloudstack/ssl/10_0_57_11-443.pem 
-----BEGIN CERTIFICATE-----
// server certificate
-----END CERTIFICATE-----

-----BEGIN CERTIFICATE-----
// chain 1
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
// chain 2
-----END CERTIFICATE-----

-----BEGIN PRIVATE KEY-----
// private key
-----END PRIVATE KEY-----
   


HAproxy configuration for the load balancer


listen 10_0_57_11-443
	bind 10.0.57.11:443 ssl crt /etc/cloudstack/ssl/10_0_57_11-443.pem alpn h2,http/1.1 ssl-min-ver TLSv1.2 no-tls-tickets ciphers ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256 ciphersuites TLS_AES_256_GCM_SHA384:TLS_AES_128_GCM_SHA256:TLS_CHACHA20_POLY1305_SHA256
	http-request add-header X-Forwarded-Proto https
	mode http
	option httpclose
	balance roundrobin
	server 10_0_57_11-443_0 10.1.1.149:80 check ssl-min-ver TLSv1.2 no-tls-tickets ciphers ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256 ciphersuites TLS_AES_256_GCM_SHA384:TLS_AES_128_GCM_SHA256:TLS_CHACHA20_POLY1305_SHA256    


4. Test plan


This is automated by test/integration/smoke/test_ssl_offloading.py

- (Optional) Generate self-signed certificate

# 1. Create isolated network and vm instance
# 2. create LB with port 80 -> 80, verify the website (should get expected content)
# 3. create LB with port 443 -> 80, verify the website (should not work)
# 4. add cert to LB with port 443
# 5. verify the website (should get expected content)
# 6. remove cert from LB with port 443
# 7. delete SSL certificate


5. References


Mozilla SSL Configuration Generator: https://ssl-config.mozilla.org/#server=haproxy&version=2.6.12&config=intermediate&openssl=3.0.16&hsts=false&guideline=5.4