Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-14705

Tech Preview - Improved TLS cipher and protocol support

XMLWordPrintable

    • Improved TLS cipher and protocol support
    • 0
    • False
    • False
    • RHOSSTRAT-600Tech Preview- Improved TLS cipher and protocol support
    • Proposed
    • Proposed
    • RHOSSTRAT-600 - Tech Preview- Improved TLS cipher and protocol support
    • openstack-octavia-8.0.1-0.20210813161814.f16f72c.el8ost
    • Proposed
    • Proposed
    • Hide
      .Improved TLS cipher and protocol support (Technology Preview)

      This update introduces a Technology Preview of improved Load-balancing service (octavia) support for TLS cipher and protocol. You can now override the default cipher list with values that are more appropriate for your site, as well as use additional new features such as setting cipher and protocol lists for each listener.
      Show
      .Improved TLS cipher and protocol support (Technology Preview) This update introduces a Technology Preview of improved Load-balancing service (octavia) support for TLS cipher and protocol. You can now override the default cipher list with values that are more appropriate for your site, as well as use additional new features such as setting cipher and protocol lists for each listener.
    • Technology Preview
    • Done

      Today the default HAProxy configuration in the Amphora provider driver does not override the default cipher list. Operators and users may want to disable weak cipher suites, for example. Operators have the ability to override that list but that is not ideal since they have to provide a custom HAProxy template file where other options other than just cipher suites need to be also set.

      • Add an ability to set default SSL ciphers in the Octavia configuration
      • Add an ability to set cipher list for each listener
      • Add the ability to set a cipher "blacklist" in the Octavia config that has disallowed ciphers
      • Add the ability to set pool ciphers used when connecting to member servers
      • Add an ability to set default SSL protocols in the Octavia configuration
      • Add an ability to set protocol list for each listener
      • Add the ability to set a protocol "blacklist" in the Octavia config that has disallowed ciphers
      • Add the ability to set pool protocols used when connecting to member servers

      https://storyboard.openstack.org/#!/story/2006627
      https://storyboard.openstack.org/#!/story/2006733
      https://review.opendev.org/#/q/%22Story:+2006627%22

              rhn-support-gthiemon Gregory Thiemonge
              jira-bugzilla-migration RH Bugzilla Integration
              rhos-dfg-networking-squad-vans
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: