-
Story
-
Resolution: Duplicate
-
Critical
-
None
-
None
-
None
-
5
-
False
-
None
-
False
-
-
-
Sprint 246, Sprint 247, Sprint 248, Sprint 249
-
0
-
0.000
We need to set upgradeable=false in 4.15 if the router cert is SHA1 because HaProxy with OpenSSL 3.0 is rejecting SHA1 certificates with ca md too weak. (CI failure). Upgradeable=false will prevent users from breaking their openshift-router when upgrading.
Story is just a reminder. This will need to be eventually tracked as bug because it needs to be backported into 4.15 (and you can't easily backport stories/epics).
- is duplicated by
-
OCPBUGS-26498 Router fails to start/reload with SHA1 cert due to OpenSSL 3.0 in RHEL9
- Closed