-
Feature Request
-
Resolution: Unresolved
-
Undefined
-
None
-
openshift-4.12
-
None
-
False
-
None
-
False
-
Not Selected
-
-
-
-
It is currently only possible to configure a TLS profiles including supported ciphers in a custom profile with
But it is not possible to control the server signature algorithm.
Customer wants to disable specific "Server Signature Algorithm(s)" based on a security audit especially
rsa_pkcs1_sha224
which is known to be weak.
There seems to be a property implemented in https://www.haproxy.com/blog/announcing-haproxy-2-8#signing-algorithms-for-tls
that could work.
We need similar config option in OpenShift.
- depends on
-
NE-1440 [Tracking Upstream] Upgrade OpenShift Router to Haproxy 2.8
- Closed