Uploaded image for project: 'Network Edge'
  1. Network Edge
  2. NE-1449

Set upgradeable=false in 4.15 if router cert is SHA1

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Duplicate
    • Icon: Critical Critical
    • None
    • None
    • None
    • Sprint 246, Sprint 247, Sprint 248, Sprint 249
    • 0
    • 0.0

      We need to set upgradeable=false in 4.15 if the router cert is SHA1 because HaProxy with OpenSSL 3.0 is rejecting SHA1 certificates with ca md too weak. (CI failure). Upgradeable=false will prevent users from breaking their openshift-router when upgrading.

      Story is just a reminder. This will need to be eventually tracked as bug because it needs to be backported into 4.15 (and you can't easily backport stories/epics).

            gspence@redhat.com Grant Spence
            gspence@redhat.com Grant Spence
            Jessica Manthei Jessica Manthei
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: