Overview Apache CloudStack provides a registerUserKeys API that allows a user to create or recreate a secret key and an API key to use for authentication when using the CloudStack API. A malicious user can request this API action in conjunction with the ID of another CloudStack user/account. The newly created or re-generated API keys for […]
Overview Apache CloudStack contains an authentication module providing “single sign-on” functionality via the SAML data format. Under certain conditions, a user could manage to access the user interface without providing proper credentials. As the SAML plugin is disabled by default, this issue only affects installations that have enabled and use SAML-based authentication. Mitigation: Users of […]
Today, Citrix announced that it was selling off two product lines: Citrix CloudPlatform and Citrix CloudPortal. For once, many Cloud commentators are right: this absolutely IS Citrix picking up its ball and going home. They’ve thrown this business line over the fence to Accelerite from Persistent Systems. However the sale tells us more about Citrix […]
https://www.shapeblue.com/wp-content/uploads/2016/01/exit-sign.jpg300300Giles Siretthttps://www.shapeblue.com/wp-content/uploads/2017/06/logo-340x156.pngGiles Sirett2016-01-12 13:24:582017-11-06 17:36:05Taxi for Citrix, now time for CloudStack to shine
We recently came across a very unusual issue where a client had a major security breach on their network. As well as lots of other damage their CloudStack infrastructure was maliciously damaged beyond recovery. Luckily the hackers hadn’t manage to damage the backend XenServer hypervisors so they were quite happily still running user VMs and Virtual Routers, […]
https://www.shapeblue.com/wp-content/uploads/2017/03/Fotolia_51644947_XS-1.jpg300300Giles Siretthttps://www.shapeblue.com/wp-content/uploads/2017/06/logo-340x156.pngGiles Sirett2015-11-19 13:48:082017-11-06 17:37:22Recovery of VMs to new CloudStack instance
Paul Angus, Cloud Architect at ShapeBlue takes an interesting look at how to separate Cloudstack’s management traffic from its primary storage traffic. I recently looked at physical networking in a CloudStack environment and alluded to the fact that you cannot separate primary storage traffic from management traffic from CloudStack, but that it is still possible. […]
Overview A vulnerability has been recently disclosed by Qualys that could result in a remote attacker being able to execute malicious instructions on vulnerable systems. The vulnerability affects Linux based operating systems. This is better known as GHOST ‘glibc’ vulnerability (CVE-2015-0235): https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0235 What is ShapeBlue Doing ShapeBlue has analysed the impact of this issue on Apache CloudStack (ACS). The […]
Update – Following community feedback, Timeout Settings have now been added to the script Update – The HA settings in this post also apply to XenServer 6.5.0 onwards Warning: If you have applied Hotfix XS62ESP1004 to your XenServer 6.2 infrastructure and have not enabled Pool HA, in the event of your Pool Master going down, […]
https://www.shapeblue.com/wp-content/uploads/2015/01/Pool-HA-300x300.jpg300300Steve Roleshttps://www.shapeblue.com/wp-content/uploads/2017/06/logo-340x156.pngSteve Roles2015-01-06 16:30:102017-11-06 17:40:47XenServer Native HA with CloudStack
Introduction If you are new to Apache CloudStack and want to learn the concepts but do not have all the equipment required to stand-up a test environment, why not use your existing PC and VirtualBox. VirtualBox is a cross platform virtualisation application which runs on OSX, Windows, Linux and Solaris, meaning no matter what OS […]
https://www.shapeblue.com/wp-content/uploads/2014/11/virtualbox.jpg300300Steve Roleshttps://www.shapeblue.com/wp-content/uploads/2017/06/logo-340x156.pngSteve Roles2014-11-18 13:17:372017-11-06 17:38:56How to Build a CloudStack Test Environment using VirtualBox
Our Autumn meetup saw us back at Trend Micro, which is becoming a home from home for us! Great to see the guys there again and many thanks for hosting another great meeting. As usual a good turn-out for the group and some really interesting discussions. Once we’d all settled Giles kicked off with the […]
https://www.shapeblue.com/wp-content/uploads/2017/04/cs-Europe-1.jpg300300Steve Roleshttps://www.shapeblue.com/wp-content/uploads/2017/06/logo-340x156.pngSteve Roles2014-10-28 12:58:562017-11-06 17:42:09CloudStack European User Group roundup – October 2014
The realhostip.com service will be switched off on the 1st October 2014. Paul Angus looks at what it did, what effect the retirement will have and what you need to do to carry on working if you’re affected. What is realhostip.com? When you connect to the Console Proxy system VM or download a disk or […]
https://www.shapeblue.com/wp-content/uploads/2016/05/Fotolia_70078651_XS-300x300.jpg300300Steve Roleshttps://www.shapeblue.com/wp-content/uploads/2017/06/logo-340x156.pngSteve Roles2014-09-29 11:05:592017-11-06 17:51:42Retirement of the realhostip.com Service