Using mutual authentication in Bluemix requires the loading of client certs or trust stores.
This is possible via the Bluemix console, but there is no way to list or view current client certs, and there is no way to upload an additional or revoke a single client cert without going through the entire upload process of server cert, private key, intermediate, and client trust store altogether again.
This method takes time and is could introduce problems if an incorrect cert is uploaded by human error. Changing a client cert should not mean having to change server certs.
When revoking access, rather than just being able to delete a cert, we have to re-upload all which again could have an impact on running services.
| Idea priority | Medium |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.
This is possible in Cloud Foundry Enterprise Environments which GA'ed last week.
Screenshot of the domain SSL in Bluemix console. There is no option to add only an individual client certificate. The upload button is only enabled when the server cert and private key are specified as well. Only then can I add an entire new client trust store. Would be good to be able to upload a single new client cert.
Not sure why you didn't see the internal comment but the question was:
Can you please provide a screenshot of where you are experiencing this?
This has been changed to 'Returned for specifics'. There is no explanation - do I need to provide further details? Is there an action on me as the requester or is it being reviewed by Cloud team?