Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-1377

BZ#1813551 Improved TLS cipher and protocol support

XMLWordPrintable

    • Improved TLS cipher and protocol support
    • 0
    • False
    • False
    • Committed
    • Proposed
    • openstack-octavia-8.0.1-0.20210813161814.f16f72c.el8ost
    • Committed
    • Proposed
    • 100% To Do, 0% In Progress, 0% Done
    • Undefined

      Today the default HAProxy configuration in the Amphora provider driver does not override the default cipher list. Operators and users may want to disable weak cipher suites, for example. Operators have the ability to override that list but that is not ideal since they have to provide a custom HAProxy template file where other options other than just cipher suites need to be also set.

      • Add an ability to set default SSL ciphers in the Octavia configuration
      • Add an ability to set cipher list for each listener
      • Add the ability to set a cipher "blacklist" in the Octavia config that has disallowed ciphers
      • Add the ability to set pool ciphers used when connecting to member servers
      • Add an ability to set default SSL protocols in the Octavia configuration
      • Add an ability to set protocol list for each listener
      • Add the ability to set a protocol "blacklist" in the Octavia config that has disallowed ciphers
      • Add the ability to set pool protocols used when connecting to member servers

      https://storyboard.openstack.org/#!/story/2006627
      https://storyboard.openstack.org/#!/story/2006733
      https://review.opendev.org/#/q/%22Story:+2006627%22

              rhn-support-gthiemon Gregory Thiemonge
              jira-bugzilla-migration RH Bugzilla Integration
              rhos-dfg-networking-squad-vans
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: