Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-91221

[RFE] podman API socket to support TLS/mTLS

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • rhel-9.6
    • podman
    • None
    • Low
    • rhel-container-tools
    • 3
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • Red Hat Enterprise Linux
    • None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      1. Proposed title of this feature request

      Podman API socket to support TLS/mTLS

      2. Who is the customer behind the request?

      Account: name and account:     Kodiak Networks/634118
      TAM customer: no
      CSM customer: no
      Strategic: no

      3. What is the nature and description of the request?

      Customer wants to expose podman API via a TCP socket. 
      Due to lack of TLS support,  the node fails CIS rule 2.7 compliance check ie "Ensure TLS authentication for Podman service is configured". They do not want to use  or maintain another software "haproxy" just for enabling TLS for podman API's TCP socket

      Upstream request
      https://github.com/containers/podman/issues/24583

      4. Why does the customer need this? (List the business requirements here)

      Customer requires TLS support for passing the CIS compliance check successfully

      5. How would the customer like to achieve this? (List the functional requirements here)

      Enhance podman API to support TLS certs

      6. For each functional requirement listed, specify how Red Hat and the customer can test to confirm the requirement is successfully implemented.

      Red Hat and Customer can test by configuring podman API socket to listen on a TCP port and with TLS certs configured

      7. Is there already an existing RFE upstream or in Red Hat Bugzilla?

      Upstream:https://github.com/containers/podman/issues/24583

      8. Does the customer have any specific timeline dependencies and which release would they like to target (i.e. RHEL8, RHEL9)?

      RHEL 8(since RHEL 8 is maintenance phase please consider it for RHEL 9 (may be not just for this customer))

      9. Is the sales team involved in this request and do they have any additional input?
      No

      10. List any affected packages or components.
      podman

      11. Would the customer be able to assist in testing this functionality if implemented?

      Customer or Support can assist

              bbaude@redhat.com Brent Baude
              rhn-support-rrajaram Ranjith Rajaram
              Container Runtime Eng Bot Container Runtime Eng Bot
              Container Runtime Bugs Bot Container Runtime Bugs Bot
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: