blob: d6545af6b559f18845042cd467c1e5a52f9568d7 [file] [log] [blame]
<!doctype html>
<html lang="en" dir="ltr" class="blog-wrapper blog-tags-post-list-page plugin-blog plugin-id-default" data-has-hydrated="false">
<head>
<meta charset="UTF-8">
<meta name="generator" content="Docusaurus v2.4.3">
<title data-rh="true">57 posts tagged with &quot;announcement&quot; | Apache CloudStack</title><meta data-rh="true" name="viewport" content="width=device-width,initial-scale=1"><meta data-rh="true" name="twitter:card" content="summary_large_image"><meta data-rh="true" property="og:url" content="https://cloudstack.apache.org/blog/tags/announcement/page/5"><meta data-rh="true" name="docusaurus_locale" content="en"><meta data-rh="true" name="docsearch:language" content="en"><meta data-rh="true" property="og:title" content="57 posts tagged with &quot;announcement&quot; | Apache CloudStack"><meta data-rh="true" name="docusaurus_tag" content="blog_tags_posts"><meta data-rh="true" name="docsearch:docusaurus_tag" content="blog_tags_posts"><link data-rh="true" rel="icon" href="/img/favicon.ico"><link data-rh="true" rel="canonical" href="https://cloudstack.apache.org/blog/tags/announcement/page/5"><link data-rh="true" rel="alternate" href="https://cloudstack.apache.org/blog/tags/announcement/page/5" hreflang="en"><link data-rh="true" rel="alternate" href="https://cloudstack.apache.org/blog/tags/announcement/page/5" hreflang="x-default"><link rel="alternate" type="application/rss+xml" href="/blog/rss.xml" title="Apache CloudStack RSS Feed">
<link rel="alternate" type="application/atom+xml" href="/blog/atom.xml" title="Apache CloudStack Atom Feed">
<script src="scripts/bootstrap.bundle.min.js" async></script><link rel="stylesheet" href="/assets/css/styles.e12efb83.css">
<link rel="preload" href="/assets/js/runtime~main.60ecdf28.js" as="script">
<link rel="preload" href="/assets/js/main.2d60fa8d.js" as="script">
</head>
<body class="navigation-with-keyboard">
<script>!function(){function t(t){document.documentElement.setAttribute("data-theme",t)}var e=function(){var t=null;try{t=new URLSearchParams(window.location.search).get("docusaurus-theme")}catch(t){}return t}()||function(){var t=null;try{t=localStorage.getItem("theme")}catch(t){}return t}();t(null!==e?e:"light")}()</script><div id="__docusaurus">
<div role="region" aria-label="Skip to main content"><a class="skipToContent_fXgn" href="#__docusaurus_skipToContent_fallback">Skip to main content</a></div><nav aria-label="Main" class="navbar navbar--fixed-top"><div class="navbar__inner"><div class="navbar__items"><button aria-label="Toggle navigation bar" aria-expanded="false" class="navbar__toggle clean-btn" type="button"><svg width="30" height="30" viewBox="0 0 30 30" aria-hidden="true"><path stroke="currentColor" stroke-linecap="round" stroke-miterlimit="10" stroke-width="2" d="M4 7h22M4 15h22M4 23h22"></path></svg></button><a class="navbar__brand" href="/"><div class="navbar__logo"><img src="/img/navlogo.png" alt="apache-cloudstack" class="themedImage_ToTc themedImage--light_HNdA"><img src="/img/navlogo.png" alt="apache-cloudstack" class="themedImage_ToTc themedImage--dark_i4oU"></div><b class="navbar__title text--truncate"></b></a></div><div class="navbar__items navbar__items--right"><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">About</a><ul class="dropdown__menu"><li><a class="dropdown__link" href="/about">About</a></li><li><a class="dropdown__link" href="/history">History</a></li><li><a class="dropdown__link" href="/features">Features</a></li><li><a class="dropdown__link" href="/who">Who We Are</a></li><li><a class="dropdown__link" href="/bylaws">Community Bylaws</a></li><li><a class="dropdown__link" href="/trademark-guidelines">Trademark Guidelines</a></li><li><a class="dropdown__link" href="/security">Security</a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">Community</a><ul class="dropdown__menu"><li><a class="dropdown__link" href="/contribute">Get Involved</a></li><li><a class="dropdown__link" href="/developers">Developer Resources</a></li><li><a class="dropdown__link" href="/mailing-lists">Join Mailing Lists</a></li><li><a href="https://github.com/apache/cloudstack/issues" target="_blank" rel="noopener noreferrer" class="dropdown__link">Issues Tracker<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://join.slack.com/t/apachecloudstack/shared_invite/zt-1u8qwbivp-u16HRI~LWioLmF1G2D3Iyg" target="_blank" rel="noopener noreferrer" class="dropdown__link">Community Slack<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a class="dropdown__link" href="/events">Events and Meetups</a></li><li><a href="https://www.cloudstackcollab.org/" target="_blank" rel="noopener noreferrer" class="dropdown__link">Collab Conference<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">Use Cases</a><ul class="dropdown__menu"><li><a class="dropdown__link" href="/cloud-builders">Cloud Builders</a></li><li><a class="dropdown__link" href="/kubernetes">Kubernetes</a></li><li><a class="dropdown__link" href="/integrations">Integrations</a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">Users</a><ul class="dropdown__menu"><li><a class="dropdown__link" href="/users">Known Users</a></li><li><a class="dropdown__link" href="/blog/tags/announcement/page/blog/tags/case-studies">Case Studies</a></li><li><a href="https://docs.google.com/forms/d/e/1FAIpQLScPHIRetdt-pxPT62IesXMoQUmhQ8ATGKcYZa507mB9uwzn-Q/viewform" target="_blank" rel="noopener noreferrer" class="dropdown__link">Take Survey<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">Documentation</a><ul class="dropdown__menu"><li><a href="https://docs.cloudstack.apache.org" target="_blank" rel="noopener noreferrer" class="dropdown__link">CloudStack Documentation<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://cwiki.apache.org/confluence/display/CLOUDSTACK/Home" target="_blank" rel="noopener noreferrer" class="dropdown__link">Project Wiki<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://cwiki.apache.org/confluence/display/CLOUDSTACK/CloudStack+Books" target="_blank" rel="noopener noreferrer" class="dropdown__link">CloudStack Books<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a class="dropdown__link" href="/api/">API Documentation</a></li></ul></div><a class="navbar__item navbar__link" href="/downloads">Download</a><a class="navbar__item navbar__link" href="/blog">Blog</a><a href="https://github.com/apache/cloudstack" target="_blank" rel="noopener noreferrer" class="navbar__item navbar__link header-github-link" aria-label="GitHub repository"></a><div class="searchBox_ZlJk"><div class="navbar__search searchBarContainer_NW3z"><input placeholder="Search" aria-label="Search" class="navbar__search-input"><div class="loadingRing_RJI3 searchBarLoadingRing_YnHq"><div></div><div></div><div></div><div></div></div><div class="searchHintContainer_Pkmr"><kbd class="searchHint_iIMx">ctrl</kbd><kbd class="searchHint_iIMx">K</kbd></div></div></div><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">ASF</a><ul class="dropdown__menu"><li><a href="https://www.apache.org/" target="_blank" rel="noopener noreferrer" class="dropdown__link">Foundation</a></li><li><a href="https://www.apache.org/licenses/" target="_blank" rel="noopener noreferrer" class="dropdown__link">License</a></li><li><a href="https://www.apache.org/events/current-event" target="_blank" rel="noopener noreferrer" class="dropdown__link">Events</a></li><li><a href="https://www.apache.org/security/" target="_blank" rel="noopener noreferrer" class="dropdown__link">Security</a></li><li><a href="https://www.apache.org/foundation/sponsorship.html" target="_blank" rel="noopener noreferrer" class="dropdown__link">Sponsorship</a></li><li><a href="https://www.apache.org/foundation/policies/privacy.html" target="_blank" rel="noopener noreferrer" class="dropdown__link">Privacy</a></li><li><a href="https://www.apache.org/foundation/thanks.html" target="_blank" rel="noopener noreferrer" class="dropdown__link">Thanks</a></li></ul></div></div></div><div role="presentation" class="navbar-sidebar__backdrop"></div></nav><div id="__docusaurus_skipToContent_fallback" class="main-wrapper mainWrapper_z2l0"><div class="container margin-vert--lg blog-container"><div class="row"><aside class="col col--3"><nav class="sidebar thin-scrollbar"><div class="sidebarItemTitle margin-bottom--md">CloudStack Blog</div><ul class="sidebarItemList clean-list"><li class="sidebarItem"><a class="sidebarItemLink" href="/blog">All Posts</a></li><li class="sidebarItem"><a class="sidebarItemLink" href="/blog/tags/news">News</a></li><li class="sidebarItem"><a aria-current="page" class="sidebarItemLink sidebarItemLinkActive" href="/blog/tags/announcement">Announcements</a></li><li class="sidebarItem"><a class="sidebarItemLink" href="/blog/tags/roundup">Past Events</a></li><li class="sidebarItem"><a class="sidebarItemLink" href="/blog/tags/case-studies">Case Studies &amp; Integrations</a></li><li class="sidebarItem"><a class="sidebarItemLink" href="/blog/tags/community">Meet the Community</a></li></ul></nav></aside><main class="col col--7" itemscope="" itemtype="http://schema.org/Blog"><header class="margin-bottom--xl"><h1>57 posts tagged with &quot;announcement&quot;</h1><a href="/blog/tags">View All Tags</a></header><article class="margin-bottom--xl" itemprop="blogPost" itemscope="" itemtype="http://schema.org/BlogPosting"><meta itemprop="description" content="CVE-2014-7807: Apache CloudStack unauthenticated LDAP binds"><header><h2 class="title_f1Hy" itemprop="headline"><a itemprop="url" href="/blog/cve_2014_7807_apache_cloudstack">[CVE-2014-7807] Apache CloudStack unauthenticated LDAP binds</a></h2><div class="container_mt6G margin-vert--md"><time datetime="2014-12-08T00:00:00.000Z" itemprop="datePublished">December 8, 2014</time></div></header><div class="markdown" itemprop="articleBody"><p>CVE-2014-7807: Apache CloudStack unauthenticated LDAP binds</p><p>CVSS:<br>7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P</p><p>Vendors:<br>The Apache Software Foundation<br>Citrix, Inc.</p><p>Versions Afffected:<br>Apache CloudStack 4.3, 4.4</p><p>Description:<br>Apache CloudStack may be configured to authenticate LDAP users. When so configured, it performs a simple LDAP bind with the name and password provided by a user. Simple LDAP binds are defined with three mechanisms (RFC 4513): 1) username and password; 2) unauthenticated if only a username is specified; and 3) anonymous if neither username or password is specified. Currently, Apache CloudStack does not check if the password was provided which could allow an attacker to bind as an unauthenticated user.</p><p>Mitigation:<br>Users of Apache CloudStack 4.4 and derivatives should update to the latest version (4.4.2)</p><p>An updated release for Apache CloudStack 4.3.2 is in testing. Until that is released, we recommend following the mitigation below:</p><p>By default, many LDAP servers are not configured to allow unauthenticated binds. If the LDAP server in use allow this behaviour, a potential interim solution would be to consider disabling unauthenticated binds.</p><p>Credit:<br>This issue was identified by the Citrix Security Team.</p></div><footer class="row docusaurus-mt-lg"><div class="col"><b>Tags:</b><ul class="tags_jXut padding--none margin-left--sm"><li class="tag_QGVx"><a class="tag_zVej tagRegular_sFm0" href="/blog/tags/announcement">announcement</a></li></ul></div></footer></article><article class="margin-bottom--xl" itemprop="blogPost" itemscope="" itemtype="http://schema.org/BlogPosting"><meta itemprop="description" content="Command Line Interface Tool Simplifies Apache CloudStack Configuration and Management"><header><h2 class="title_f1Hy" itemprop="headline"><a itemprop="url" href="/blog/the_apache_cloudstack_project_announces1">The Apache CloudStack Project Announces Apache™ CloudMonkey™ v5.3.0</a></h2><div class="container_mt6G margin-vert--md"><time datetime="2014-11-11T00:00:00.000Z" itemprop="datePublished">November 11, 2014</time></div></header><div class="markdown" itemprop="articleBody"><em><h2>Command Line Interface Tool Simplifies Apache CloudStack Configuration and Management</h2></em><p>11 November 2014 —Apache CloudStack, the mature, turnkey Open Source cloud computing software platform used for creating private, public, and hybrid cloud environments, today announced Apache CloudMonkey v5.3.0, the latest feature release of its command line interface tool.</p><p>CloudMonkey is written in Python, and can be used both as an interactive shell and as a command line tool that simplifies CloudStack configuration and management.</p><p>Apache CloudMonkey v5.3.0 is the latest feature release of the 5.x line that was first released in September 2013. Some of the new features and changes include:</p><ul><li>Unicode support in CloudMonkey;</li><li>Better autocompletion for API arguments, filter arguments and config options;</li><li>Current server profile is displayed on the prompt;</li><li>Changing server profile prints masked values of passwords and keys;</li><li>New command line argument -d for display options such as default, json and table;</li><li>New config option “verifysslcert” that enables/disables SSL certificate checking when making HTTP API calls;</li><li>CloudMonkey outputs without color on terminal in non-interactive mode;</li><li>Better error handling, errors written to stderr and non-zero exit codes in case of error;</li><li>Several bugfixes related to networking, server profiles and unicode string handling</li></ul><p></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="downloadsanddocumentation">Downloads and Documentation<a href="#downloadsanddocumentation" class="hash-link" aria-label="Direct link to Downloads and Documentation" title="Direct link to Downloads and Documentation"></a></h3><p></p><p>The official source code for CloudMonkey v5.3.0 can be downloaded from <a href="http://cloudstack.apache.org/downloads.html" target="_blank" rel="noopener noreferrer">http://cloudstack.apache.org/downloads.html</a>. A community-maintained distribution is available at the Python Package Index (PyPi) at <a href="http://pypi.python.org/pypi/CloudMonkey/" target="_blank" rel="noopener noreferrer">http://pypi.python.org/pypi/CloudMonkey/</a></p><p>CloudMonkey&#x27;s usage is documented at <a href="https://cwiki.apache.org/confluence/display/CLOUDSTACK/CloudStack+CloudMonkey+CLI" target="_blank" rel="noopener noreferrer">https://cwiki.apache.org/confluence/display/CLOUDSTACK/CloudStack+CloudMonkey+CLI</a>Package documentation can be found at <a href="http://pythonhosted.org/cloudmonkey/" target="_blank" rel="noopener noreferrer">http://pythonhosted.org/cloudmonkey/</a></p><p></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="availabilityandoversight">Availability and Oversight<a href="#availabilityandoversight" class="hash-link" aria-label="Direct link to Availability and Oversight" title="Direct link to Availability and Oversight"></a></h3><p></p><p>As with all Apache products, CloudMonkey is released under the Apache License v2.0, and is overseen by a self-selected team of active contributors to the project. The Apache CloudStack Project Management Committee (PMC) guides the Project&#x27;s day-to-day operations, including community development and product releases.</p><p></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="aboutapachecloudstack">About Apache CloudStack<a href="#aboutapachecloudstack" class="hash-link" aria-label="Direct link to About Apache CloudStack" title="Direct link to About Apache CloudStack"></a></h3><p></p><p>Apache CloudStack is a mature, turnkey integrated Infrastructure-as-a-Service (IaaS) Open Source software platform that allows users to build feature-rich public and private cloud environments. Hailed by Gartner Group as &quot;a solid product&quot;, CloudStack includes an intuitive user interface and rich APIs for managing the compute, networking, software, and storage infrastructure resources. CloudStack entered the Apache Incubator in April 2012 and became an Apache Top-level Project in March 2013. For downloads, documentation, and ways to become involved with Apache CloudStack, visit <a href="http://cloudstack.apache.org/" target="_blank" rel="noopener noreferrer">http://cloudstack.apache.org/</a> and <a href="https://twitter.com/CloudStack" target="_blank" rel="noopener noreferrer">https://twitter.com/CloudStack</a></p><h1></h1></div><footer class="row docusaurus-mt-lg"><div class="col"><b>Tags:</b><ul class="tags_jXut padding--none margin-left--sm"><li class="tag_QGVx"><a class="tag_zVej tagRegular_sFm0" href="/blog/tags/announcement">announcement</a></li></ul></div></footer></article><article class="margin-bottom--xl" itemprop="blogPost" itemscope="" itemtype="http://schema.org/BlogPosting"><meta itemprop="description" content="Mature, easy-to-deploy Open Source Cloud computing software platform boasts improved efficiency and performance."><header><h2 class="title_f1Hy" itemprop="headline"><a itemprop="url" href="/blog/announcing_apache_cloudstack_v4_4">Announcing Apache™ CloudStack™ v4.4.1</a></h2><div class="container_mt6G margin-vert--md"><time datetime="2014-10-23T00:00:00.000Z" itemprop="datePublished">October 23, 2014</time></div></header><div class="markdown" itemprop="articleBody"><em><h2>Mature, easy-to-deploy Open Source Cloud computing software platform boasts improved efficiency and performance.</h2></em><p>The Apache CloudStack project announced the immediate availability of Apache CloudStack v4.4.1, the latest version of the turnkey Open Source cloud computing software platform used for creating private-, public-, and hybrid cloud environments.</p><p>Apache CloudStack clouds enable billions of dollars&#x27; worth of business transactions annually across their clouds, and its maturity and stability has led it to has become the Open Source platform for many service providers to set up on-demand, elastic public cloud computing services, as well as enterprises and others to set up a private or hybrid cloud for use by their own employees.</p><p>&quot;We are delighted to be releasing version 4.4.1 of Apache CloudStack,&quot; said Giles Sirett, member of the Apache CloudStack Project Management Committee. &quot;This latest version of CloudStack reflects months of hard work by our diverse developer community and brings even more features to help our service-provider and enterprise users enhance their cloud platforms. Apache CloudStack continues to grow in both deployments and developer community size, and is the platform of choice for thousands of organisations that need to build IaaS environments quickly and securely with a proven, production-grade, technology.&quot;</p><p>Lauded by Gartner Group, CloudStack includes an intuitive user interface and rich APIs for managing the compute, networking, software, and storage infrastructure resources.</p><p>CloudStack v4.4.1 reflects dozens of new features and improvements, including:</p><ul><li>Improved Storage Management</li><li>Virtual Private Cloud tiers can now span guest networks across availability zones</li><li>Support for VMware Distributed Resource Scheduler</li><li>Improved Support for Hyper-V Zones, VPC and Storage Migration</li></ul><p>A complete overview of all new enhancements can be found in the project release notes at http://docs.cloudstack.apache.org/projects/cloudstack-release-notes/en/4.4.1/</p><p>CloudStack has been used by thousands of organizations worldwide and is in use/production at Alcatel-Lucent, Autodesk, BT Cloud, China Telecom, DATACAENTER Services, DataPipe, Edmunds.com, Exoscale, GreenQloud, Hokkaido University, IDC Frontier, Ikoula, KDDI, KT/Korea Telecom, LeaseWeb, NTT, Orange, PCextreme, Schuberg Philis, Shopzilla, Slovak Telekom, SunGard AS, Taiwan Mobile, Tata, Trader Media Group, TomTom, University of Melbourne, University of Sao Paolo, Verizon, WebMD and Zynga, among others.</p><p>CloudStack originated at Cloud.com, which was acquired by Citrix in 2011. CloudStack was submitted to the Apache Incubator in April 2012 and graduated as an Apache Software Foundation Top-level Project in March 2013.</p><p></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="availability">Availability<a href="#availability" class="hash-link" aria-label="Direct link to Availability" title="Direct link to Availability"></a></h3><p></p><p>CloudStack v4.4.1 is available immediately as a free download from http://cloudstack.apache.org/downloads.html. Apache CloudStack software is released under the Apache License v2.0.</p><p></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="governanceandoversight">Governance and Oversight<a href="#governanceandoversight" class="hash-link" aria-label="Direct link to Governance and Oversight" title="Direct link to Governance and Oversight"></a></h3><p></p><p>Apache CloudStack is overseen by a self-selected team of active contributors to the project. A Project Management Committee (PMC) guides the Project&#x27;s day-to-day operations, including community development and product releases.</p><p></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="getinvolved">Get Involved!<a href="#getinvolved" class="hash-link" aria-label="Direct link to Get Involved!" title="Direct link to Get Involved!"></a></h3><p></p><p>Apache CloudStack welcomes contribution and community participation through mailing lists as well as attending face-to-face MeetUps, developer trainings, and user events. Catch CloudStack in action at the CloudStack Collaboration Conference, the official user/developer conference of the Apache CloudStack community, 19-21 November 2014 in Budapest, Hungary @CCCEU14 and <a href="http://cloudstackcollab.org" target="_blank" rel="noopener noreferrer">http://cloudstackcollab.org</a></p><p></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="aboutapachecloudstack">About Apache CloudStack<a href="#aboutapachecloudstack" class="hash-link" aria-label="Direct link to About Apache CloudStack" title="Direct link to About Apache CloudStack"></a></h3><p></p><p>Apache CloudStack is a mature, turnkey integrated Infrastructure-as-a-Service (IaaS) Open Source software platform that allows users to build feature-rich public and private cloud environments. Hailed by Gartner Group as &quot;a solid product&quot;, CloudStack includes an intuitive user interface and rich APIs for managing the compute, networking, software, and storage infrastructure resources. CloudStack entered the Apache Incubator in April 2012 and became an Apache Top-level Project in March 2013. For downloads, documentation, and ways to become involved with Apache CloudStack, visit <a href="http://cloudstack.apache.org/" target="_blank" rel="noopener noreferrer">http://cloudstack.apache.org/</a> and <a href="https://twitter.com/CloudStack" target="_blank" rel="noopener noreferrer">https://twitter.com/CloudStack</a></p><h1></h1><p>© The Apache Software Foundation. &quot;Apache&quot;, &quot;CloudStack&quot;, &quot;Apache CloudStack&quot;, the Apache CloudStack logo, and the Apache CloudStack Cloud Monkey logo are registered trademarks or trademarks of The Apache Software Foundation. All other brands and trademarks are the property of their respective owners.</p></div><footer class="row docusaurus-mt-lg"><div class="col"><b>Tags:</b><ul class="tags_jXut padding--none margin-left--sm"><li class="tag_QGVx"><a class="tag_zVej tagRegular_sFm0" href="/blog/tags/announcement">announcement</a></li></ul></div></footer></article><article class="margin-bottom--xl" itemprop="blogPost" itemscope="" itemtype="http://schema.org/BlogPosting"><meta itemprop="description" content="Command Line Interface Tool Simplifies Apache CloudStack Configuration and Management"><header><h2 class="title_f1Hy" itemprop="headline"><a itemprop="url" href="/blog/announcing_apache_cloudmonkey_v5_2">Announcing Apache™ CloudMonkey™ v5.2.0</a></h2><div class="container_mt6G margin-vert--md"><time datetime="2014-08-28T00:00:00.000Z" itemprop="datePublished">August 28, 2014</time></div></header><div class="markdown" itemprop="articleBody"><em><h2>Command Line Interface Tool Simplifies Apache CloudStack Configuration and Management</h2></em><p>28 August 2014 —Apache CloudStack, the mature, turnkey Open Source cloud computing software platform used for creating private, public, and hybrid cloud environments, today announced Apache CloudMonkey v5.2.0, the latest feature release of its command line interface tool.</p><p>CloudMonkey is written in Python, and can be used both as an interactive shell and as a command line tool that simplifies CloudStack configuration and management.</p><p>Apache CloudMonkey v5.2.0 is the latest feature release of the 5.x line that was first released in September 2013. Some of the new features and changes include:</p><ul><li>Multiple server profiles where users can use CloudMonkey against different CloudStack management servers and switch between them using a profile option;</li><li>A default profile under the section [local] is added with default values;</li><li>Some bugfixes related to network requests, error handling, JSON decoding and shell interactivity;</li><li>Every time &#x27;set&#x27; is called, CloudMonkey will write the config and reload config file;</li><li>Configuration options &#x27;protocol&#x27;, &#x27;host&#x27;, &#x27;port&#x27;, &#x27;path&#x27; are deprecated now but setting them is still allowed which sets a single &quot;url&quot; option, in the config file the [server] section is deprecated now and CloudMonkey won’t read values from this section anymore but instead read from current server profile;</li><li>Missing key/values are automatically set with defaults by CloudMonkey;</li><li>During installation and upgrades, it will detect the platform to install either pyreadline (Windows) or readline (OSX and Linux);</li></ul><p></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="downloadsanddocumentation">Downloads and Documentation<a href="#downloadsanddocumentation" class="hash-link" aria-label="Direct link to Downloads and Documentation" title="Direct link to Downloads and Documentation"></a></h3><p></p><p>The official source code for CloudMonkey v5.2.0 can be downloaded from <a href="http://cloudstack.apache.org/downloads.html" target="_blank" rel="noopener noreferrer">http://cloudstack.apache.org/downloads.html</a>. A community-maintained distribution is available at the Python Package Index (PyPi) at <a href="http://pypi.python.org/pypi/CloudMonkey/" target="_blank" rel="noopener noreferrer">http://pypi.python.org/pypi/CloudMonkey/</a></p><p>CloudMonkey&#x27;s usage is documented at <a href="https://cwiki.apache.org/confluence/display/CLOUDSTACK/CloudStack+CloudMonkey+CLI" target="_blank" rel="noopener noreferrer">https://cwiki.apache.org/confluence/display/CLOUDSTACK/CloudStack+CloudMonkey+CLI</a>Package documentation can be found at <a href="http://pythonhosted.org/cloudmonkey/" target="_blank" rel="noopener noreferrer">http://pythonhosted.org/cloudmonkey/</a></p><p></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="availabilityandoversight">Availability and Oversight<a href="#availabilityandoversight" class="hash-link" aria-label="Direct link to Availability and Oversight" title="Direct link to Availability and Oversight"></a></h3><p></p><p>As with all Apache products, CloudMonkey is released under the Apache License v2.0, and is overseen by a self-selected team of active contributors to the project. The Apache CloudStack Project Management Committee (PMC) guides the Project&#x27;s day-to-day operations, including community development and product releases.</p><p></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="aboutapachecloudstack">About Apache CloudStack<a href="#aboutapachecloudstack" class="hash-link" aria-label="Direct link to About Apache CloudStack" title="Direct link to About Apache CloudStack"></a></h3><p></p><p>Apache CloudStack is a mature, turnkey integrated Infrastructure-as-a-Service (IaaS) Open Source software platform that allows users to build feature-rich public and private cloud environments. Hailed by Gartner Group as &quot;a solid product&quot;, CloudStack includes an intuitive user interface and rich APIs for managing the compute, networking, software, and storage infrastructure resources. CloudStack entered the Apache Incubator in April 2012 and became an Apache Top-level Project in March 2013. For downloads, documentation, and ways to become involved with Apache CloudStack, visit <a href="http://cloudstack.apache.org/" target="_blank" rel="noopener noreferrer">http://cloudstack.apache.org/</a> and <a href="https://twitter.com/CloudStack" target="_blank" rel="noopener noreferrer">https://twitter.com/CloudStack</a></p><h1></h1></div><footer class="row docusaurus-mt-lg"><div class="col"><b>Tags:</b><ul class="tags_jXut padding--none margin-left--sm"><li class="tag_QGVx"><a class="tag_zVej tagRegular_sFm0" href="/blog/tags/announcement">announcement</a></li></ul></div></footer></article><article class="margin-bottom--xl" itemprop="blogPost" itemscope="" itemtype="http://schema.org/BlogPosting"><meta itemprop="description" content="UPDATE 1: The instructions below are incomplete. The proper upgrade command is &quot;apt-get install openssl libssl1.0.0&quot;. If you&#x27;ve just updated openssl, please go back and update libssl as well."><header><h2 class="title_f1Hy" itemprop="headline"><a itemprop="url" href="/blog/how_to_mitigate_openssl_heartbleed">How to Mitigate OpenSSL HeartBleed Vulnerability in Apache CloudStack</a></h2><div class="container_mt6G margin-vert--md"><time datetime="2014-04-09T00:00:00.000Z" itemprop="datePublished">April 9, 2014</time></div></header><div class="markdown" itemprop="articleBody"><b>UPDATE 1:</b> The instructions below are incomplete. The proper upgrade command is &quot;apt-get install openssl libssl1.0.0&quot;. If you&#x27;ve just updated openssl, please go back and update libssl as well.<br><b>UPDATE 2:</b> Adding instructions for VMWare-hosted System VMs (Thanks to Geoff Higginbottom at ShapeBlue)<br><b>UPDATE 3:</b> Added instructions for verification of correct versions installed<br><b>UPDATE 4:</b> Apache CloudStack 4.0-4.1 not vulnerable, they use older Debian/openssl.<br><p>Earlier this week, a security vulnerability was disclosed in OpenSSL, one of the software libraries that Apache CloudStack uses to encrypt data sent over network connections. As the vulnerability has existed in OpenSSL since early 2012, System VMs in Apache CloudStack versions 4.1.1-4.3 are running software using vulnerable versions of OpenSSL. This includes CloudStack&#x27;s Virtual Router VMs, Console Proxy VMs, and Secondary Storage VMs.</p><p>We are actively working on creating updated System VM templates for each recent version of Apache CloudStack, and for each of the hypervisor platforms which Apache CloudStack supports. Due to our testing and QA processes, this will take several days. In the meantime, we want to provide our users with a temporary workaround for currently running System VMs.</p><p>If you are running Apache CloudStack 4.0.0-incubating through the recent 4.3 release, the following steps will help ensure the security of your cloud infrastructure until an updated version of the System VM template is available:</p><h2> For KVM/Xen hosted systems</h2><ol><li> As an administrator in the CloudStack web UI, navigate to Infrastructure-&gt;System VMs</li><li> For each System VM listed, note the host it is running on, and it’s “Link Local IP address.&quot;</li><li> With that data, perform the following steps for each System VM:<ol type="a"><li> ssh into that host as root</li><li> From the host, ssh into the SSVM via it’s link local IP address: (e.g. ssh -i /root/.ssh/id_rsa.cloud -p 3922 169.254.3.33)</li><li> On the System VM, first run &quot;apt-get update&quot;</li><li> Then run apt-get install &quot;openssl libssl1.0.0&quot;. If a dialog appears asking to restart programs, accept it’s request.</li><li> Next, for Secondary Storage VMs, run /etc/init.d/apache2 restart</li><li> Log out of the System VM and host server</li></ol></li><li>Back in the CloudStack UI, now navigate to Infrastructure-&gt;Virtual Routers. For each VR, host it&#x27;s running on and it&#x27;s link local IP address, and then repeat steps a-f above.</li></ol><h2> For VMWare hosted systems</h2><ol><li> As an administrator in the CloudStack web UI, navigate to Infrastructure-&gt;System VMs</li><li> For each System VM listed, note it&#x27;s management IP address</li><li> With that data, perform the following steps for each System VM:</li><li> From the Management Server, ssh to the System VM via it&#x27;s management IP: (eg ssh -i /var/lib/cloud/management/.ssh/id_rsa -p 3922 root@10.40.50.8)</li><li> On the System VM, first run &quot;apt-get update&quot;</li><li> Then run apt-get install &quot;openssl libssl1.0.0&quot;. If a dialog appears asking to restart programs, accept it’s request.</li><li> Next, for Secondary Storage VMs, run /etc/init.d/apache2 restart</li><li> Log out of the System VM</li><li>Back in the CloudStack UI, now navigate to Infrastructure-&gt;Virtual Routers. For each VR, host it&#x27;s running on and it&#x27;s link local IP address, and then repeat steps a-f above.</li></ol><h2>Verification</h2><p>On each System VM, you can test if it has non-vulnerable openssl packages installed by listing installed packages and looking at the installed versions of openssl and libssl. As in the example below, for a system to be non-vulnerable, the packages need to be at or above version 1.0.1e-2+deb7u6:</p><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#393A34;--prism-background-color:#f6f8fa"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#393A34"><span class="token plain">root@v-14-VM:~# dpkg -l|grep ssl ii libssl1.0.0:i386 1.0.1e-2+deb7u6 i386 SSL shared libraries ii openssl 1.0.1e-2+deb7u6 i386 Secure Socket Layer (SSL) binary and related cryptographic tools</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg viewBox="0 0 24 24" class="copyButtonIcon_y97N"><path fill="currentColor" d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg viewBox="0 0 24 24" class="copyButtonSuccessIcon_LjdS"><path fill="currentColor" d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><p>We realize that for larger installations where System VMs are being actively created and destroyed based on customer demand, this is a very rough stop-gap. The Apache CloudStack security team is actively working on a more permanent fix and will be releasing that to the community as soon as possible.</p><p>For Apache CloudStack installations that secure the web-based user-interface with SSL, these may also be vulnerable to HeartBleed, but that is outside the scope of this blog post. We recommend testing your installation with [1] to determine if you need to patch/upgrade the SSL library used by any web servers (or other SSL-based services) you use.</p><a href="http://filippo.io/Heartbleed/" target="_new" rel="noopener noreferrer">http://filippo.io/Heartbleed/</a></div><footer class="row docusaurus-mt-lg"><div class="col"><b>Tags:</b><ul class="tags_jXut padding--none margin-left--sm"><li class="tag_QGVx"><a class="tag_zVej tagRegular_sFm0" href="/blog/tags/announcement">announcement</a></li></ul></div></footer></article><article class="margin-bottom--xl" itemprop="blogPost" itemscope="" itemtype="http://schema.org/BlogPosting"><meta itemprop="description" content="Flexible, scalable, Open Source Infrastructure as a Service (IaaS) used by organizations such as Zynga, Datapipe, and ISWest, among others, for creating, managing, and deploying public, private, and hybrid Cloud Computing environments"><header><h2 class="title_f1Hy" itemprop="headline"><a itemprop="url" href="/blog/announcing_apache_cloudstack_4_3">Announcing Apache CloudStack 4.3.0</a></h2><div class="container_mt6G margin-vert--md"><time datetime="2014-03-25T00:00:00.000Z" itemprop="datePublished">March 25, 2014</time></div></header><div class="markdown" itemprop="articleBody"><p>Flexible, scalable, Open Source Infrastructure as a Service (IaaS) used by organizations such as Zynga, Datapipe, and ISWest, among others, for creating, managing, and deploying public, private, and hybrid Cloud Computing environments</p><p>Forest Hill, MD --25 March 2014-- The Apache Software Foundation (ASF), the all-volunteer developers, stewards, and incubators of more than 170 Open Source projects and initiatives, today announced Apache CloudStack v4.3, the latest feature release of the CloudStack cloud orchestration platform.</p><p>Apache CloudStack is an integrated Infrastructure-as-a-Service (IaaS) software platform that allows users to build feature-rich public, private, and hybrid cloud environments. CloudStack includes an intuitive user interface and rich APIs for managing the compute, networking, software, and storage infrastructure resources. CloudStack became an Apache Top-level Project (TLP) in March 2013. &quot;We are proud to announce CloudStack v4.3,&quot; said Hugo Trippaers, Vice President of Apache CloudStack. &quot;This release represents over six months of work from the Apache CloudStack community with many new and improved features.&quot;</p><h3>Under The Hood</h3><p>CloudStack V4.3 is the next feature release of the 4.x line which first released on November 6, 2012. Some of the noteworthy new and improved features include:</p><ul><li>Support for Microsoft Hyper-V - Apache CloudStack can now manage Hyper-V hypervisors in addition to KVM, XenServer, VMware, LXC, and Bare Metal</li><li>Juniper OpenContrail integration - OpenContrail is a software defined networking controller from Juniper that CloudStack now integrates with to provide SDN services</li><li>SSL Termination support for guest VMs - Apache CloudStack can configure and manage SSL termination in certain load balancer devices</li><li>Palo Alto Firewall integration - Apache CloudStack can now manage and configure Palo Alto firewalls</li><li>Remote access VPN for VPC networks - CloudStack&#x27;s remote access VPN is now available for Virtual Private Cloud networks</li><li>Site to Site VPN between VRs - CloudStack now allows site-to-site VPN connectivity to it&#x27;s virtual routing devices. This permits your cloud computing environment to appear as a natural extension of your local network, or for you to easily interconnect multiple environments</li><li>VXLAN support expansion to include KVM - CloudStack&#x27;s support for integrating VXLAN, the network virtualization technology that attempts to ameliorate scalability problems with traditional networking</li><li>SolidFire plugin extension to support KVM and hypervisor snapshots for XenServer and ESX - SolidFire provides guaranteed Storage Quality of Service at the Virtual Machine level</li><li>Dynamic Compute offering - CloudStack now has the ability to dynamically scale the resources assigned to a running virtual machine instance for those hypervisors which support it</li></ul><h3>Downloads and Documentation</h3><p>The official source code for the v4.3 release, as well as individual contributors&#x27; convenience binaries, can be downloaded from the Apache CloudStack downloads page at <a href="http://cloudstack.apache.org/downloads.html" target="_blank" rel="noopener noreferrer">http://cloudstack.apache.org/downloads.html</a></p><p>The CloudStack 4.3 release includes over 110 issues from 4.2.0 and 4.2.1, including fixes for object storage support, documentation, and more. A full list of corrected issues and upgrade instructions are available in the Release Notes <a href="http://docs.cloudstack.apache.org/projects/cloudstack-release-notes" target="_blank" rel="noopener noreferrer">http://docs.cloudstack.apache.org/projects/cloudstack-release-notes</a></p><p>Official installation, administration, and API documentation for each release is available at <a href="http://docs.cloudstack.apache.org/en/latest/" target="_blank" rel="noopener noreferrer">http://docs.cloudstack.apache.org/en/latest/</a>Apache CloudStack in Action</p><p>Join members of the Apache CloudStack community at the CloudStack Collaboration Conference, taking place 9-11 April 2014 immediately following ApacheCon. For more information, visit <a href="http://cloudstackcollab.org" target="_blank" rel="noopener noreferrer">http://cloudstackcollab.org</a></p><h3>Availability and Oversight</h3><p>As with all Apache products, Apache CloudStack v4.3 is released under the Apache License v2.0, and is overseen by a self-selected team of active contributors to the project. A Project Management Committee (PMC) guides the Project’s day-to-day operations, including community development and product releases. For documentation and ways to become involved with Apache CloudStack, visit http://cloudstack.apache.org/</p><h3>About The Apache Software Foundation (ASF)</h3><p>Established in 1999, the all-volunteer Foundation oversees more than one hundred and seventy leading Open Source projects, including Apache HTTP Server --the world&#x27;s most popular Web server software. Through the ASF&#x27;s meritocratic process known as &quot;The Apache Way,&quot; more than 400 individual Members and 3,500 Committers successfully collaborate to develop freely available enterprise-grade software, benefiting millions of users worldwide: thousands of software solutions are distributed under the Apache License; and the community actively participates in ASF mailing lists, mentoring initiatives, and ApacheCon, the Foundation&#x27;s official user conference, trainings, and expo. The ASF is a US 501(c)(3) charitable organization, funded by individual donations and corporate sponsors including Budget Direct, Citrix, Cloudera, Comcast, Facebook, Google, Hortonworks, HP, Huawei, IBM, InMotion Hosting, Matt Mullenweg, Microsoft, Pivotal, Produban, WANdisco, and Yahoo.</p><p>For more information, visit http://www.apache.org/ or follow @TheASF on Twitter.</p><p>&quot;Apache&quot;, &quot;CloudStack&quot;, &quot;Apache CloudStack&quot;, and &quot;ApacheCon&quot; are trademarks of The Apache Software Foundation. All other brands and trademarks are the property of their respective owners.</p></div><footer class="row docusaurus-mt-lg"><div class="col"><b>Tags:</b><ul class="tags_jXut padding--none margin-left--sm"><li class="tag_QGVx"><a class="tag_zVej tagRegular_sFm0" href="/blog/tags/announcement">announcement</a></li></ul></div></footer></article><article class="margin-bottom--xl" itemprop="blogPost" itemscope="" itemtype="http://schema.org/BlogPosting"><meta itemprop="description" content="Recently the Apache CloudStack PMC was informed that the realhostip.com Dynamic DNS service that CloudStack currently uses as part of the console proxy will be disbanded this summer. The realhostip service will be shut down June 30th, 2014, meaning users have approximately 3 months to mitigate this."><header><h2 class="title_f1Hy" itemprop="headline"><a itemprop="url" href="/blog/realhostip_service_is_being_retired">Realhostip Service is Being Retired</a></h2><div class="container_mt6G margin-vert--md"><time datetime="2014-03-25T00:00:00.000Z" itemprop="datePublished">March 25, 2014</time></div></header><div class="markdown" itemprop="articleBody"><p>Recently the Apache CloudStack PMC was informed that the realhostip.com Dynamic DNS service that CloudStack currently uses as part of the console proxy will be disbanded this summer. The realhostip service will be <b>shut down June 30th, 2014, meaning users have approximately 3 months to mitigate this</b>.</p><p>Prior to version 4.3, CloudStack used the realhostip.com service by default. With the release of CloudStack version 4.3 the default communication method with the console proxy is plaintext HTTP.</p><h3>Who is Affected</h3><p>CloudStack installations prior to version 4.3 that have not been reconfigured to use a DNS domain other than realhostip.com for Console Proxy or Secondary Storage must make changes to continue functioning past June 30th, 2014.</p><h3>Steps You Need to Take</h3><p>If you meet the criteria above, there are several options to prepare for realhostip retirement:</p><ul><li> Set up wildcard SSL certificate and DNS entries: This method is already well supported within prior versions of CloudStack.</li><li> Upgrade to CloudStack 4.3 and disable SSL: This is only recommended for development installations, or private clouds that contain no information of importance.</li><li> Upgrade to CloudStack 4.3, set up static SSL certificate and configure load balancer to point to the correct IP address: While this allows an administrator to skip setting up the DNS entries from the previous option, it is a more advanced option as CloudStack 4.3 does not support automatic load balancer configuration for the Console Proxy. It is hoped this functionality will be available in future releases.</li></ul><p><b>For instructions</b> on how to set up SSL encryption for use with CloudStack console proxy, please read the <a href="http://docs.cloudstack.apache.org/projects/cloudstack-administration/en/latest/systemvm.html#console-proxy" target="_blank" rel="noopener noreferrer">console proxy section of the CloudStack administration guide</a>.</p><p>Additionally, if you will be using an SSL vendor who requires an intermediate CA chain to be installed for proper SSL validation by web browsers, detailed instructions for configuring the intermediate CA chain in CloudStack can be found <a href="http://www.chipchilders.com/blog/2013/1/2/undocumented-feature-using-certificate-chains-in-cloudstack.html" target="_blank" rel="noopener noreferrer">here</a>.</p><p><i>The Apache CloudStack security team does not recommend running a production cloud with either the realhostip.com SSL certificate, or with no SSL encryption at all.</i></p></div><footer class="row docusaurus-mt-lg"><div class="col"><b>Tags:</b><ul class="tags_jXut padding--none margin-left--sm"><li class="tag_QGVx"><a class="tag_zVej tagRegular_sFm0" href="/blog/tags/announcement">announcement</a></li></ul></div></footer></article><article class="margin-bottom--xl" itemprop="blogPost" itemscope="" itemtype="http://schema.org/BlogPosting"><meta itemprop="description" content="The Apache CloudStack project is pleased to announce the 4.2.1 release of the CloudStack cloud orchestration platform. This is a minor release of the 4.2.0 branch which released on Oct 1, 2013. The 4.2.1 release contains more than 150 bug fixes. As a bug fix release, no new features are included in 4.2.1."><header><h2 class="title_f1Hy" itemprop="headline"><a itemprop="url" href="/blog/announcing_apache_cloudstack_4_21">Announcing Apache CloudStack 4.2.1</a></h2><div class="container_mt6G margin-vert--md"><time datetime="2014-01-10T00:00:00.000Z" itemprop="datePublished">January 10, 2014</time></div></header><div class="markdown" itemprop="articleBody"><p>The Apache CloudStack project is pleased to announce the 4.2.1 release of the CloudStack cloud orchestration platform. This is a minor release of the 4.2.0 branch which released on Oct 1, 2013. The 4.2.1 release contains more than 150 bug fixes. As a bug fix release, no new features are included in 4.2.1.</p><p>The 4.2.1 release includes fixes for a number of issues; including problems with Xenserver VMSnapshots, UCS, device ID for Xen, configurable option to choose single Vs multipart upload for S3 API, allowing network with public IP Address without needing SourceNAT, and documentation fixes.</p><p>As a minor release it is a simple upgrade from 4.2.0 with no architectural changes. CloudStack Management Servers Services, and all SystemVMs will require a restart.</p><p>This release also addresses two security issues CVE-2013-6398 and CVE-2014-0031</p><p><strong>Documentation</strong></p><p>The 4.2.1 release notes includes full list of corrected issues as well as upgrade instructions from previous versions of Apache CloudStack. Please see the <a href="http://cloudstack.apache.org/docs/en-US/Apache_CloudStack/4.2.1/html/Release_Notes/index.html" target="_blank" rel="noopener noreferrer">Release Notes</a> for a full list of corrected issues and upgrade instructions.</p><p>The official installation, administration and API documentation for each release are available on our <a href="http://cloudstack.apache.org/docs" target="_blank" rel="noopener noreferrer">Documentation Page</a>.</p><p><strong>Downloads</strong></p><p>The official source code for the 4.2.1 release can be downloaded from our <a href="http://cloudstack.apache.org/downloads.html" target="_blank" rel="noopener noreferrer">Downloads Page</a>.</p><p>In addition to the official source code release, individual contributors have also made convenience binaries in the form or RPM and Deb packages available from the download page. </p><p><strong>About Apache CloudStack</strong></p><p>Apache CloudStack is an integrated Infrastructure-as-a-Service (IaaS) software platform that allows users to build feature-rich public and private cloud environments. CloudStack includes an intuitive user interface and rich APIs for managing the compute, networking, software, and storage infrastructure resources. The project became an Apache top level project in March 2013.</p><p>For additional marketing or communications information, please contact the <a href="mailto:marketing@cloudstack.apache.org" target="_blank" rel="noopener noreferrer">marketing mailing list</a>.</p><p>To learn how to join and contribute to the Apache CloudStack community please visit our <a href="http://cloudstack.apache.org" target="_blank" rel="noopener noreferrer">website</a>.</p></div><footer class="row docusaurus-mt-lg"><div class="col"><b>Tags:</b><ul class="tags_jXut padding--none margin-left--sm"><li class="tag_QGVx"><a class="tag_zVej tagRegular_sFm0" href="/blog/tags/announcement">announcement</a></li></ul></div></footer></article><article class="margin-bottom--xl" itemprop="blogPost" itemscope="" itemtype="http://schema.org/BlogPosting"><meta itemprop="description" content="Product: Apache CloudStack"><header><h2 class="title_f1Hy" itemprop="headline"><a itemprop="url" href="/blog/cve_2013_6398_cloudstack_virtual">[CVE-2013-6398] CloudStack Virtual Router stop/start modifies firewall rules allowing additional access</a></h2><div class="container_mt6G margin-vert--md"><time datetime="2014-01-10T00:00:00.000Z" itemprop="datePublished">January 10, 2014</time></div></header><div class="markdown" itemprop="articleBody"><p>Product: Apache CloudStack<br>Vendor: Apache Software Foundation<br>Vulnerability type: Bypass<br>Vulnerable Versions: Apache CloudStack 4.1.0, 4.1.1, 4.2.0<br>CVE References: CVE-2013-2136<br>Risk Level: Low<br>CVSSv2 Base Scores: 2.8 (AV:N/AC:M/Au:M/C:P/I:N/A:N)<br></p><p>Description:</p><p>The Apache CloudStack Security Team was notified of a an issue in the Apache CloudStack virtual router that failed to preserve source restrictions in firewall rules after a virtual router had been stopped and restarted.</p><p>Mitigation:</p><p>Upgrading to CloudStack 4.2.1 or higher will mitigate this issue.</p><p>References:</p><p>https://issues.apache.org/jira/browse/CLOUDSTACK-5263</p><p>Credit:</p><p>This issue was identified by the Cloud team at Schuberg Philis</p></div><footer class="row docusaurus-mt-lg"><div class="col"><b>Tags:</b><ul class="tags_jXut padding--none margin-left--sm"><li class="tag_QGVx"><a class="tag_zVej tagRegular_sFm0" href="/blog/tags/announcement">announcement</a></li></ul></div></footer></article><article class="margin-bottom--xl" itemprop="blogPost" itemscope="" itemtype="http://schema.org/BlogPosting"><meta itemprop="description" content="Product: Apache CloudStack"><header><h2 class="title_f1Hy" itemprop="headline"><a itemprop="url" href="/blog/cve_2014_0031_cloudstack_listnetworkacl">[CVE-2014-0031] CloudStack ListNetworkACL API discloses ACLs for other users</a></h2><div class="container_mt6G margin-vert--md"><time datetime="2014-01-10T00:00:00.000Z" itemprop="datePublished">January 10, 2014</time></div></header><div class="markdown" itemprop="articleBody"><p>Product: Apache CloudStack<br>Vendor: Apache Software Foundation<br>Vulnerability type: Information Disclosure<br>Vulnerable Versions: Apache CloudStack 4.2.0<br>CVE References: CVE-2014-0031<br>Risk Level: Low<br>CVSSv2 Base Scores: 3.5 (AV:N/AC:M/Au:S/C:P/I:N/A:N)<br></p><p>Description:</p><p>The Apache CloudStack Security Team was notified of a an issue in Apache CloudStack which permits an authenticated user to list network ACLs for other users.</p><p>Mitigation:</p><p>Upgrading to CloudStack 4.2.1 or higher will mitigate this issue.</p><p>References:</p><p>https://issues.apache.org/jira/browse/CLOUDSTACK-5145</p><p>Credit:</p><p>This issue was identified by Marcus Sorensen</p></div><footer class="row docusaurus-mt-lg"><div class="col"><b>Tags:</b><ul class="tags_jXut padding--none margin-left--sm"><li class="tag_QGVx"><a class="tag_zVej tagRegular_sFm0" href="/blog/tags/announcement">announcement</a></li></ul></div></footer></article><nav class="pagination-nav" aria-label="Blog list page navigation"><a class="pagination-nav__link pagination-nav__link--prev" href="/blog/tags/announcement/page/4"><div class="pagination-nav__label">Newer Entries</div></a><a class="pagination-nav__link pagination-nav__link--next" href="/blog/tags/announcement/page/6"><div class="pagination-nav__label">Older Entries</div></a></nav></main></div></div></div><footer class="footer footer--dark"><div class="container container-fluid"><div class="footer__bottom text--center"><div class="margin-bottom--sm"><a href="https://cloudstack.apache.org/" rel="noopener noreferrer" class="footerLogoLink_BH7S"><img src="/img/ACS_logo_slogan.svg" alt="Apache CloudStack logo" class="themedImage_ToTc themedImage--light_HNdA footer__logo"><img src="/img/ACS_logo_slogan.svg" alt="Apache CloudStack logo" class="themedImage_ToTc themedImage--dark_i4oU footer__logo"></a></div><div class="footer__copyright">
<div class="social">
<a href="mailto:dev-subscribe@cloudstack.apache.org">
<img src="/img/mail_mini_icon.svg" alt="">
</a>
<a href="https://join.slack.com/t/apachecloudstack/shared_invite/zt-2aegc22z7-tPCxpptfcebTBtd59qcZSQ">
<img src="/img/slack_mini_icon.svg" alt="">
</a>
<a href="https://github.com/apache/cloudstack">
<img src="/img/git_mini_icon.svg" alt="">
</a>
<a href="https://twitter.com/CloudStack">
<img src="/img/twitter_X_mini_icon.svg" alt="">
</a>
<a href="https://www.youtube.com/@ApacheCloudStack">
<img src="/img/youtube_mini_icon.svg" alt="">
</a>
<a href="https://www.linkedin.com/company/apachecloudstack/posts/">
<img src="/img/linkedin_icon.svg" alt="">
</a>
</div>
<div class="footer-bottom">Copyright © 2023 The Apache
Software Foundation, Licensed under the Apache License, Version 2.0.
“Apache”, “CloudStack”, “Apache CloudStack”, the Apache CloudStack logo,
the Apache CloudStack Cloud Monkey logo and the Apache feather logos
are registered trademarks or trademarks of The Apache Software
Foundation.
<p class="footer-blue"><a href="/trademark-guidelines">Apache CloudStack Trademark Usage</a> - <a href="/bylaws">Apache CloudStack Community ByLaws</a> - <a href="https://github.com/apache/cloudstack-www">Website Source Code</a></p></div>
</div>
<br>
</div></div></footer></div>
<script src="/assets/js/runtime~main.60ecdf28.js"></script>
<script src="/assets/js/main.2d60fa8d.js"></script>
</body>
</html>