Jira (PUP-10889) Explicitly set default ciphersuites to avoid surprises

19 views
Skip to first unread message

Josh Cooper (Jira)

unread,
Feb 5, 2021, 2:12:04 PM2/5/21
to puppe...@googlegroups.com
Josh Cooper created an issue
 
Puppet / Improvement PUP-10889
Explicitly set default ciphersuites to avoid surprises
Issue Type: Improvement Improvement
Assignee: Unassigned
Created: 2021/02/05 11:11 AM
Priority: Normal Normal
Reporter: Josh Cooper

Puppet uses whatever ciphersuites ruby and the openssl it was compiled with supports. To avoid surprises, puppet should explicitly set what ciphersuites we support and allow it to be configurable.

 

Add Comment Add Comment
 
This message was sent by Atlassian Jira (v8.5.2#805002-sha1:a66f935)
Atlassian logo

Josh Cooper (Jira)

unread,
Feb 5, 2021, 3:34:02 PM2/5/21
to puppe...@googlegroups.com

Josh Cooper (Jira)

unread,
Feb 5, 2021, 3:35:04 PM2/5/21
to puppe...@googlegroups.com

Josh Cooper (Jira)

unread,
Feb 5, 2021, 3:39:04 PM2/5/21
to puppe...@googlegroups.com
Josh Cooper updated an issue
Change By: Josh Cooper
Sprint: Platform Core KANBAN

Josh Cooper (Jira)

unread,
Mar 2, 2021, 6:53:56 PM3/2/21
to puppe...@googlegroups.com
Josh Cooper updated an issue
Change By: Josh Cooper
Fix Version/s: PUP 7.5.0
Fix Version/s: PUP 6.22.0

Josh Cooper (Jira)

unread,
Mar 2, 2021, 6:58:57 PM3/2/21
to puppe...@googlegroups.com
Josh Cooper updated an issue
Change By: Josh Cooper
Release Notes: Enhancement
Release Notes Summary: Adds a "ciphers" puppet setting to configure which TLS ciphersuites the agent supports. The default set of ciphersuites is the same as what it was before this change, but the list of ciphersuites can be made more restricted if desired, such as to only accept TLS v1.2 ciphersuites.

Josh Cooper (Jira)

unread,
Mar 2, 2021, 7:18:56 PM3/2/21
to puppe...@googlegroups.com

Josh Cooper (Jira)

unread,
Mar 4, 2021, 1:14:03 PM3/4/21
to puppe...@googlegroups.com
Josh Cooper updated an issue
Change By: Josh Cooper
Release Notes Summary: Adds a "ciphers" puppet setting to configure which TLS ciphersuites the agent supports. The default set of ciphersuites is the same as what it was before this change, but the list of ciphersuites can be made more restricted if desired, such as to only accept TLS v1.2 or greater ciphersuites.

Josh Cooper (Jira)

unread,
Mar 9, 2021, 3:20:01 PM3/9/21
to puppe...@googlegroups.com

Claire Cadman (Jira)

unread,
Mar 10, 2021, 10:37:03 AM3/10/21
to puppe...@googlegroups.com
Reply all
Reply to author
Forward
0 new messages