Server's name isn't verified when using https

Bug #1079692 reported by Stuart McLaren
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Glance Client
Fix Released
Low
Stuart McLaren

Bug Description

When using https Glance doesn't check the name (CN/subjectAltName) in the x509 cert against the host that its connected to.

Changed in python-glanceclient:
assignee: nobody → Stuart McLaren (stuart-mclaren)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to python-glanceclient (master)

Fix proposed to branch: master
Review: https://review.openstack.org/16305

Changed in python-glanceclient:
status: New → In Progress
Brian Waldon (bcwaldon)
Changed in python-glanceclient:
importance: Undecided → Low
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to python-glanceclient (master)

Reviewed: https://review.openstack.org/16305
Committed: http://github.com/openstack/python-glanceclient/commit/7a5946fd87bc78b9d302ba6b665283e9744c8cd8
Submitter: Jenkins
Branch: master

commit 7a5946fd87bc78b9d302ba6b665283e9744c8cd8
Author: Stuart McLaren <email address hidden>
Date: Fri Nov 16 13:46:59 2012 +0000

    Verify that host matches certificate

    When using https verify that the Common Name (CN) or
    the Subject Alternative Name listed in the server's
    certificate match the host we are connected to.

    Addresses LP bug 1079692.

    Change-Id: I24ea1511a2cbdb7c34ce72ac704d7b5e7d57cec2

Changed in python-glanceclient:
status: In Progress → Fix Committed
Brian Waldon (bcwaldon)
Changed in python-glanceclient:
milestone: none → v0.7.0
Brian Waldon (bcwaldon)
Changed in python-glanceclient:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.