Uploaded image for project: 'OpenShift Service Mesh'
  1. OpenShift Service Mesh
  2. OSSM-11493

Assess impact of OpenSSL ENGINE API removal on HSM integrations

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • None
    • Release Engineering
    • None

      RHEL 10 removes the OpenSSL ENGINE API in favor of the OpenSSL 3.x Provider API.
       
      We need to audit Service Mesh deployments using Hardware Security Modules (HSM) for CA or private keys to:

      • Identify dependencies on the deprecated OpenSSL ENGINE API.
      • Investigate the feasibility of migrating to the pkcs11-provider mechanism.
      • Determine the engineering effort required to re-architect HSM integrations for OpenSSL 3.x compliance.

              Unassigned Unassigned
              rhn-support-rzago Rafael Zago
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: