Orion Context Broker HTTPS for Subscribers

The very simple question is: Does the Orion Context Broker support SSL for subscribers:

Example. Can a subscription callback url be https://mysimpleexample.com/notify

I tried this (using a trusted certificate!) And this does not seem to work for me.

However, I do not start the Orion Context Broker using the -https option. However, looking at the manual, this option seems to be used to use SSL on the context broker HTTP server and has nothing to do with client subscription.

Edit: I tried this on the http endpoint, and then on the https endpoint with the same host name afterwards. Only the https endpoint had problems.

+2
source share
1 answer

You are right: -https CLI is the activation of HTTPS in the ORION NGSI API (on the one hand). It is not associated with notifications sent by Orion.

Orion does not support HTTPS notifications directly (on the client side), but functionality can be achieved using an HTTP relay such as Rush . Using the HTTP broker has additional advantages, such as freeing Orion from troubleshooting notification failures, retries, etc.

Orion-Rush integration has not yet been achieved, but it is on our short-term roadmap. Please take a look (and finally subscribe if you want to know when the functionality will be implemented), https://github.com/telefonicaid/fiware-orion/issues/251

UPDATE: Orion-Rush integration for HTTPS was implemented in Orion 0.13.0. See the Security Considerations section of the Orion User Guide.

UPDATE: Rush has been added as part of the global context management instance, so CB on orion.lab.fi-ware.org nos supports HTTPS notifications. However, the CB error currently ignores the default port for the https URL scheme, so use 443 explicitly (e.g. https: https://foo.bar:443/path ).

UPDATE: The bug mentioned in the previous update note is fixed in Orion version 0.17.0.

UPDATE: starting from version 1.7.0, Orion implements its own HTTPS notifications (i.e., without the need for Rush).

0
source

Source: https://habr.com/ru/post/1208188/


All Articles