apache / apache/cloudstack

Error tying to register ISO/Template with DirectDownload over HTTPS with Let's Encrypt

未關閉
#12,878 2 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視
component:kvm component:templates no-issue-activity
主要語言
Java
星號
3.1k
分支
1.4k
平均合併
6 天 19 小時
30 天內合併 PR
32

描述

### problem

When using the "Direct Download" feature for an ISO or Template (bypassing Secondary Storage), the Agent fails to verify Let's Encrypt certificates due to the absence of Let's Encrypt’s main CA certificate.

> Note: Let's Encrypt is widely used on the internet (>50% of all certificates).

ACS currently loads and trusts certificates exclusively from `/etc/cloudstack/agent/cloud.jks` and does not fall back to Java (`/usr/lib/jvm/java-17-openjdk-amd64/lib/security/cacerts`) or the system store (`/etc/ssl/certs/ca-certificates.crt`). Both of these contain the missing certificate (**ISRG Root X1**), which has been in use since 2015.

See: https://letsencrypt.org/certificates/

Image

**ISRG Root X1** is the current root of the trust chain (valid until 2030), after which it will be replaced by **ISRG Root X2**.

**Recommendation:** Add a fallback to Java’s trust store to avoid maintaining an ever-changing list of certificates.

**Alternative:** As a short-term fix, include the missing CA certificate (https://letsencrypt.org/certs/isrgrootx1.pem) in `/etc/cloudstack/agent/cloud.jks` for the next release, while a more sustainable solution is developed.

### versions

We are running ACS 4.20.2 on Ubuntu 24.04. However, this issue likely affects all versions starting from 4.19, when the feature to bypass Secondary Storage was introduced.

Related issues and PRs:
- https://github.com/apache/cloudstack/issues/7929
- https://github.com/apache/cloudstack/pull/7693/changes
- https://github.com/apache/cloudstack/pull/7923/changes
- https://github.com/apache/cloudstack/pull/7932/changes
- https://github.com/apache/cloudstack/pull/11113/changes

### The steps to reproduce the bug

1. When registering an ISO or Template for Direct Download, use any HTTPS URL whose TLS certificate is issued by Let's Encrypt.

### What to do about it?

As a workaround, the following command can be run for each Zone to add the missing certificate. Note that this introduces additional manual steps for platform maintenance:

```
cmk upload templatedirectdownloadcertificate hypervisor="KVM" name="isrg-root-x1-2" certific
ate="$(curl -s https://letsencrypt.org/certs/isrgrootx1.pem)" zoneid="00000000-0000-0000-00000-000000000000"
```

貢獻指南

開啟貢獻指南

研究方向

從 Agent 的憑證處理和 `/etc/cloudstack/agent/cloud.jks` 開始,然後將其與 Java 的 `/usr/lib/jvm/java-17-openjdk-amd64/lib/security/cacerts` 以及位於 `/etc/ssl/certs/ca-certificates.crt` 的系統存放區進行比較。使用 Let's Encrypt,針對 HTTPS URL 重現 ISO 或 Template 的直接下載,並考慮相關的 issue 和 PR;完成的標準是 Agent 無需針對每個 Zone 進行手動 workaround 即可驗證憑證。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
java
領域
backend, cloud, infrastructure
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
活躍
描述清晰度
基本清楚
新手友好度
48/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。