Uploaded image for project: 'Infinispan'
  1. Infinispan
  2. ISPN-14114

Enabling TLS 1.3 is impossible

This issue belongs to an archived project. You can view it, but you can't modify it. Learn more

XMLWordPrintable

      The cipher selection configuration is inadequate for TLS 1.3. We need to distinguish between ciphersuite filters (TLS 1.2 and below) and ciphersuite names (TLS 1.3).
      The following is an example:

      <security-realm name="default">
               <server-identities>
                  <ssl>
                     <engine enabled-protocols="TLSv1.3 TLSv1.2" enabled-ciphersuites-filter="TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384" enabled-ciphersuites-names="TLS_AES_256_GCM_SHA384"/>
                  </ssl>
               </server-identities>
            </security-realm>

      We should also provide proper defaults for the filters and names.

      For filters, we use DEFAULT
      For names, we use TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256

              ttarrant@redhat.com Tristan Tarrant
              ttarrant@redhat.com Tristan Tarrant
              Archiver:
              rhn-support-adongare Amol Dongare

                Created:
                Updated:
                Resolved:
                Archived: