Uploaded image for project: 'OpenShift Virtualization'
  1. OpenShift Virtualization
  2. CNV-22162

[2139235] unlike other CNV components, Kubevirt uses its own cipher for tls 1.2

XMLWordPrintable

    • CNV Virtualization Sprint 231, CNV Virtualization Sprint 232
    • High
    • None

      Description of problem:
      HCO and SSP need to have ECDHE-ECDSA-AES128-GCM-SHA256 cipher enabled

      But Kubevirt needs ECDHE-RSA-AES128-GCM-SHA256

      Not sure if it is by design, but personally I would think we need adhere to the same standard.
      Currently, we have to be sure that both of these ciphers are present, otherwise some components become non-responding

      Version-Release number of selected component (if applicable):
      4.12

      Actual results:
      CNV components use different ciphers

      Expected results:
      CNV components use the same cipher

              ffossemo@redhat.com Federico Fossemo
              dshchedr@redhat.com Denys Shchedrivyi
              Kedar Bidarkar Kedar Bidarkar
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: