• Icon: Task Task
    • Resolution: Unresolved
    • Icon: Blocker Blocker
    • None
    • None
    • Logging
    • 13
    • False
    • Hide

      None

      Show
      None
    • False

      "Information from Alan:
      recently openshift introduced a cluster-wide ""TLS profile"" giving preferred TLS config (allowed encryption algorithms etc.) for anything running in the cluster.

      We implemented it in the CLO, so we respect the cluster-wide profile if there is one, I think we also allow setting your own profile on the CLO. There's an epic with lnked stuff here: https://issues.redhat.com/browse/LOG-3270 also the OCP docs have some description of the global profile - it affects many things besides logging e.g. the API server and other ""infrastructure"" stufff.

      Note the global TLS profile only affects things that choose to obey it - so openshift services, logging etc. It can't impose its will on random other services that a customer might run in the cluster."

              Unassigned Unassigned
              bdooley@redhat.com Brian Dooley
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: