Uploaded image for project: 'Maistra'
  1. Maistra
  2. MAISTRA-1921

Enable proxy to run within a FIPS environment

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: Major Major
    • maistra-1.1.10
    • None
    • None
    • MAISTRA 1.1.10

      Proxy fails to start because of the following error

      [Envoy (Epoch 0)] [2020-10-08 00:02:55.108][16][critical][main] [external/envoy/source/server/server.cc:98] error initializing configuration '/etc/istio/proxy/envoy-rev0.json': Failed to initialize cipher suites [ECDHE-ECDSA-AES128-GCM-SHA256|ECDHE-ECDSA-CHACHA20-POLY1305]:[ECDHE-RSA-AES128-GCM-SHA256|ECDHE-RSA-CHACHA20-POLY1305]:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:AES128-GCM-SHA256:AES128-SHA:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:AES256-GCM-SHA384:AES256-SHA. The following ciphers were rejected when tried individually: ECDHE-ECDSA-CHACHA20-POLY1305, ECDHE-RSA-CHACHA20-POLY1305

        1. cmd.sh
          0.3 kB
        2. httpbin.example.com.crt
          1 kB
        3. httpbin.example.com.csr
          0.9 kB
        4. httpbin.example.com.key
          2 kB
        5. httpbin.yaml
          2 kB

              yuaxu@redhat.com Yuanlin Xu
              kconner@redhat.com Kevin Conner (Inactive)
              Votes:
              1 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: