Server's name isn't verified when using https

Bug #1079692 reported by Stuart McLaren on 2012-11-16
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Stuart McLaren

Bug Description

When using https Glance doesn't check the name (CN/subjectAltName) in the x509 cert against the host that its connected to.

Changed in python-glanceclient:
assignee: nobody → Stuart McLaren (stuart-mclaren)

Fix proposed to branch: master

Changed in python-glanceclient:
status: New → In Progress
Brian Waldon (bcwaldon) on 2012-11-20
Changed in python-glanceclient:
importance: Undecided → Low

Submitter: Jenkins
Branch: master

commit 7a5946fd87bc78b9d302ba6b665283e9744c8cd8
Author: Stuart McLaren <email address hidden>
Date: Fri Nov 16 13:46:59 2012 +0000

    Verify that host matches certificate

    When using https verify that the Common Name (CN) or
    the Subject Alternative Name listed in the server's
    certificate match the host we are connected to.

    Addresses LP bug 1079692.

    Change-Id: I24ea1511a2cbdb7c34ce72ac704d7b5e7d57cec2

Changed in python-glanceclient:
status: In Progress → Fix Committed
Brian Waldon (bcwaldon) on 2012-12-11
Changed in python-glanceclient:
milestone: none → v0.7.0
Brian Waldon (bcwaldon) on 2012-12-12
Changed in python-glanceclient:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers