Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Application Client-only certificates are not tied to a specific machine.  They function just like people, only it is expected that they are used within "keystores" as identity when talking to AAF enabled components.

PLEASE USE your APP NAME IN CI/CD (OOM, etc) in your request.  That makes the most sense for identity.

Automation and tracking of Application Certificates will be proposed for Casablanca. 

In the meantime, for testing purposes, you may request a certificate from AAF team, see process.

Application Service 

This kind of Certificate must have the Machine Name in the "CN=" position.  

AAF supports Automated Certificate Deployment, but this has not been integrated with OOM at this time (April 12, 2018).  

    • Please request Manual Certificate, but specify the Machine as well.  Machine should be a name, so you might need to provide your Clients with instructions on adding to /etc/hosts until ONAP address Name Services for ONAP Environments (i.e. DNS)

GUI

https://aaf-onap-beijing-test.osaaf.org

...