<!-- 
RSS generated by JIRA (8.20.10#820010-sha1:ace47f9899e9ee25d7157d59aa17ab06aee30d3d) at Wed Feb 07 20:37:19 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>OpenDaylight JIRA</title>
    <link>https://jira.opendaylight.org</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>8.20.10</version>
        <build-number>820010</build-number>
        <build-date>22-06-2022</build-date>
    </build-info>


<item>
            <title>[RELENG-30] https SSL cert by using StartCom as a CA is a PITA</title>
                <link>https://jira.opendaylight.org/browse/RELENG-30</link>
                <project id="10164" key="RELENG">releng</project>
                    <description>&lt;p&gt;Thanh &amp;amp; Co, are you sure that using the https SSL cert on &lt;a href=&quot;https://nexus.opendaylight.org&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://nexus.opendaylight.org&lt;/a&gt; and &lt;a href=&quot;https://git.opendaylight.org&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://git.opendaylight.org&lt;/a&gt; with StartCom as a CA is a good idea?&lt;/p&gt;

&lt;p&gt;This is causing PITA issues such as:&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://blog2.vorburger.ch/2016/04/how-to-resolve-validatorexception-pkix.html&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;http://blog2.vorburger.ch/2016/04/how-to-resolve-validatorexception-pkix.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://bugs.eclipse.org/bugs/show_bug.cgi?id=492014&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://bugs.eclipse.org/bugs/show_bug.cgi?id=492014&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Couldn&apos;t we just use a https SSL cert on *.opendaylight.org issued/signed by a &quot;more standard&quot; CA whose root cert is part of all Java installations, to avoid people wasting time on issues like above?&lt;/p&gt;</description>
                <environment>&lt;p&gt;Operating System: All&lt;br/&gt;
Platform: All&lt;/p&gt;</environment>
        <key id="19438">RELENG-30</key>
            <summary>https SSL cert by using StartCom as a CA is a PITA</summary>
                <type id="10104" iconUrl="https://jira.opendaylight.org/secure/viewavatar?size=xsmall&amp;avatarId=10303&amp;avatarType=issuetype">Bug</type>
                                                <status id="5" iconUrl="https://jira.opendaylight.org/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="green"/>
                                    <resolution id="10003">Cannot Reproduce</resolution>
                                        <assignee username="-1">Unassigned</assignee>
                                    <reporter username="vorburger">Michael Vorburger</reporter>
                        <labels>
                    </labels>
                <created>Tue, 26 Apr 2016 10:03:35 +0000</created>
                <updated>Tue, 28 Nov 2017 16:11:05 +0000</updated>
                            <resolved>Tue, 28 Nov 2017 16:11:05 +0000</resolved>
                                    <version>unspecified</version>
                                                    <component>Autorelease</component>
                        <due></due>
                            <votes>0</votes>
                                    <watches>3</watches>
                                                                                                                <comments>
                            <comment id="35244" author="vorburger" created="Fri, 29 Apr 2016 16:46:19 +0000"  >&lt;p&gt;FTR: This &lt;a href=&quot;https://lists.opendaylight.org/pipermail/dev/2016-April/thread.html#1866&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://lists.opendaylight.org/pipermail/dev/2016-April/thread.html#1866&lt;/a&gt; thread highlights that other users are having similar problems ...&lt;/p&gt;</comment>
                            <comment id="35245" author="agrimberg" created="Fri, 6 May 2016 15:58:17 +0000"  >&lt;p&gt;(In reply to Michael Vorburger from comment #0)&lt;br/&gt;
&amp;gt; Thanh &amp;amp; Co, are you sure that using the https SSL cert on&lt;br/&gt;
&amp;gt; &lt;a href=&quot;https://nexus.opendaylight.org&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://nexus.opendaylight.org&lt;/a&gt; and &lt;a href=&quot;https://git.opendaylight.org&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://git.opendaylight.org&lt;/a&gt; with&lt;br/&gt;
&amp;gt; StartCom as a CA is a good idea?&lt;br/&gt;
&amp;gt; &lt;br/&gt;
&amp;gt; This is causing PITA issues such as:&lt;br/&gt;
&amp;gt; &lt;br/&gt;
&amp;gt; &lt;a href=&quot;http://blog2.vorburger.ch/2016/04/how-to-resolve-validatorexception-pkix.html&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;http://blog2.vorburger.ch/2016/04/how-to-resolve-validatorexception-pkix.html&lt;/a&gt;&lt;br/&gt;
&amp;gt; &lt;br/&gt;
&amp;gt; &lt;a href=&quot;https://bugs.eclipse.org/bugs/show_bug.cgi?id=492014&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://bugs.eclipse.org/bugs/show_bug.cgi?id=492014&lt;/a&gt;&lt;br/&gt;
&amp;gt; &lt;br/&gt;
&amp;gt; Couldn&apos;t we just use a https SSL cert on *.opendaylight.org issued/signed by&lt;br/&gt;
&amp;gt; a &quot;more standard&quot; CA whose root cert is part of all Java installations, to&lt;br/&gt;
&amp;gt; avoid people wasting time on issues like above?&lt;/p&gt;

&lt;p&gt;Our Nexus system uses a certificate from COMODO because of issues with JAVA. When we had first moved the system into our private cloud there was a mistake with the setup and had applied our * cert to the system.&lt;/p&gt;

&lt;p&gt;Gerrit on the other hand, uses our * cert and will continue to do so. StartCom is a &quot;more standard&quot; CA, it&apos;s recognized by all browsers and Java installations &lt;em&gt;except&lt;/em&gt; for Oracle&apos;s Java. As long as you&apos;re accessing Gerrit from Java via the SSH (preferred) interface you shouldn&apos;t have any issues.&lt;/p&gt;

&lt;p&gt;We have plans to eventually switch all of our certs to using Let&apos;s Encrypt, which is also supported by the Oracle Java, but there is still integration work with our management frameworks that has to happen before that&apos;s an option.&lt;/p&gt;</comment>
                            <comment id="35246" author="vorburger" created="Tue, 10 May 2016 09:39:29 +0000"  >&lt;p&gt;&amp;gt; StartCom is a &quot;more standard&quot; CA, it&apos;s recognized by all browsers and Java installations &lt;em&gt;except&lt;/em&gt; for Oracle&apos;s Java. &lt;/p&gt;

&lt;p&gt;Oh OK I didn&apos;t realize that this was Oracle Java specific, but OK with Open JDK.. perhaps less of a blocking issue then.  Thanks for clarifying, noted.&lt;/p&gt;

&lt;p&gt;&amp;gt; As long as you&apos;re accessing Gerrit from Java via the SSH (preferred) interface you shouldn&apos;t have any issues.&lt;/p&gt;

&lt;p&gt;In &lt;a href=&quot;https://bugs.eclipse.org/bugs/show_bug.cgi?id=492014&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://bugs.eclipse.org/bugs/show_bug.cgi?id=492014&lt;/a&gt; I had faced problems accessing Gerrit via &lt;a href=&quot;https://www.eclipse.org/egerrit/&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://www.eclipse.org/egerrit/&lt;/a&gt; which talks https to the Gerrit REST API. &lt;/p&gt;

&lt;p&gt;The git clone ssh always works fine of course, yes.&lt;/p&gt;</comment>
                            <comment id="35247" author="vorburger" created="Tue, 24 May 2016 10:06:15 +0000"  >&lt;p&gt;Andrew &amp;amp; Thanh, just FYI: This &lt;b&gt;IS&lt;/b&gt; a PITA - I&apos;ve just had someone else reach out to me on private IRC DM struggling with this AGAIN.  Now it was because that user tried to install yangide from &lt;a href=&quot;https://nexus.opendaylight.org/content/sites/p2repos/org.opendaylight.yangide/snapshot/content.xml&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://nexus.opendaylight.org/content/sites/p2repos/org.opendaylight.yangide/snapshot/content.xml&lt;/a&gt; using &lt;a href=&quot;https://github.com/vorburger/opendaylight-eclipse-setup&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://github.com/vorburger/opendaylight-eclipse-setup&lt;/a&gt;, and hit this..&lt;/p&gt;

&lt;p&gt;Just adding actual error message to be able to find this issue more easily again in the future, it&apos;s: &quot;javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target&quot;&lt;/p&gt;</comment>
                            <comment id="60242" author="zxiiro" created="Tue, 28 Nov 2017 15:20:01 +0000"  >&lt;p&gt;&lt;a href=&quot;https://jira.opendaylight.org/secure/ViewProfile.jspa?name=vorburger&quot; class=&quot;user-hover&quot; rel=&quot;vorburger&quot;&gt;vorburger&lt;/a&gt; is this still an issue? I haven&apos;t heard of SSL issues recently so thinking perhaps this can be closed now. Also I believe we&apos;re now using&#160;LetsEncrypt.&lt;/p&gt;</comment>
                            <comment id="60250" author="vorburger" created="Tue, 28 Nov 2017 16:11:05 +0000"  >&lt;p&gt;I&apos;ve not heard of this issue in a long time either, so let us just close it now.&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                            <customfield id="customfield_11400" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                        <customfield id="customfield_10208" key="com.atlassian.jira.plugin.system.customfieldtypes:textfield">
                        <customfieldname>External issue ID</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>5806</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10201" key="com.atlassian.jira.plugin.system.customfieldtypes:url">
                        <customfieldname>External issue URL</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue><![CDATA[https://bugs.opendaylight.org/show_bug.cgi?id=5806]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_10000" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0|i01m47:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>