Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-37706

Modern TLS security profile support

XMLWordPrintable

    • Quality / Stability / Reliability
    • False
    • Hide

      None

      Show
      None
    • None
    • Important
    • None
    • Rejected
    • Auth Feature Team - Sprint 268, Auth Feature Team - Sprint 269
    • 2
    • +
    • Proposed
    • Release Note Not Required
    • The "Modern" TLS security profile was documented as supported in 4.16, but it didn't actually work, support for TLS 1.3 and proper handling of the Modern profile was added in 4.19, ensuring the profile now works as expected

      Description of problem:

      Modern TLS security profile is one of 4.16 we support, see https://docs.openshift.com/container-platform/4.16/security/tls-security-profiles.html, but actually it dones't work.
      
          

      Version-Release number of selected component (if applicable):

      $ oc get clusterversion
      NAME      VERSION                              AVAILABLE   PROGRESSING   SINCE   STATUS
      version   4.16.0-0.nightly-2024-08-21-192930   True        False         5h42m   Cluster version is 4.16.0-0.nightly-2024-08-21-192930
      
          

      How reproducible:

      always
          

      Steps to Reproduce:

          1. $ oc patch apiservers/cluster --type=merge -p '{"spec": {"tlsSecurityProfile":{"modern":{},"type":"Modern"}}}'
      The APIServer "cluster" is invalid: spec.tlsSecurityProfile.type: Unsupported value: "Modern": supported values: "Old", "Intermediate", "Custom"
          

      Actual results:

          Modern TLS security profile doesn't work
          

      Expected results:

          Modern TLS security profile should work
      
          

      Additional info:

      
          

              rhn-gps-jasee Jacob See
              wk2019 Ke Wang
              None
              None
              Rahul Gangwar Rahul Gangwar
              None
              Votes:
              0 Vote for this issue
              Watchers:
              11 Start watching this issue

                Created:
                Updated:
                Resolved: