ClearOS Bug Tracker


View Issue Details Jump to Notes ] Issue History ] Print ]
IDProjectCategoryView StatusDate SubmittedLast Update
0018371ClearOSapp-marketplace - Marketplacepublic2017-12-20 05:522017-12-20 19:53
ReporterNickH 
Assigned To 
PrioritynormalSeveritytweakReproducibilityalways
StatusconfirmedResolutionopen 
PlatformOSOS Version
Product Version7.4.0 Updates 
Target VersionFixed in Version 
Summary0018371: Remove references to OpenVPN in the Let's Encrypt app in the Marketplace
DescriptionIn the marketplace widget for Let's Encrypt it says:
"Let's Encrypt is an open certificate authority that provides free SSL certificates. The app intelligently integrates the certificate lifecyle and management into Webconfig to be used by other services - Webconfig, website hosting, Openfire, OpenVPN etc."

This has been reported on the forum: https://www.clearos.com/clearfoundation/social/community/howto-letsencrypt-free-certficates-for-clearos-7-3#reply-201181 [^]

I do not believe the certificates integrate with OpenVPN at all and may give a big security risk if they did (OpenVPN only really checks if the certificate is signed by the same CA that the OpenVPN server uses which would enable anyone with a Let's Encrypt certificate to pass the certificate part of the OpenVPN validation).

..... and if fixing it, change the typo "lifecyle" to "lifecycle".
TagsNo tags attached.
Attached Files

- Relationships

-  Notes
There are no notes attached to this issue.

- Issue History
Date Modified Username Field Change
2017-12-20 05:52 NickH New Issue
2017-12-20 19:53 pbaldwin Status new => confirmed
2017-12-20 19:53 pbaldwin Product Version 7.4.0 => 7.4.0 Updates