Browse Source

Force force-tlsv12 only

Secure by default

Change-Id: Id8262de092f0f2820a4cedab6f9d0e48a0c06f3a
Matthew Thode 4 months ago
parent
commit
21e4fdfd0c
No account linked to committer's email address
2 changed files with 8 additions and 1 deletions
  1. 1
    1
      defaults/main.yml
  2. 7
    0
      releasenotes/notes/tls12-only-9b74e96cfd47a634.yaml

+ 1
- 1
defaults/main.yml View File

@@ -147,7 +147,7 @@ gnocchi_ssl: false
147 147
 gnocchi_ssl_cert: /etc/ssl/certs/gnocchi.pem
148 148
 gnocchi_ssl_key: /etc/ssl/private/gnocchi.key
149 149
 gnocchi_ssl_ca_cert: /etc/ssl/certs/gnocchi-ca.pem
150
-gnocchi_ssl_protocol: "{{ ssl_protocol | default('ALL -SSLv2 -SSLv3') }}"
150
+gnocchi_ssl_protocol: "{{ ssl_protocol | default('ALL -SSLv2 -SSLv3 -TLSv1.0 -TLSv1.1') }}"
151 151
 gnocchi_ssl_cipher_suite: "{{ ssl_cipher_suite | default('ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:RSA+AESGCM:RSA+AES:!aNULL:!MD5:!DSS') }}"
152 152
 
153 153
 # if using a self-signed certificate, set this to true to regenerate it

+ 7
- 0
releasenotes/notes/tls12-only-9b74e96cfd47a634.yaml View File

@@ -0,0 +1,7 @@
1
+---
2
+security:
3
+  - |
4
+    The default TLS version has been set to TLS1.2.  This only allows
5
+    version 1.2 of the protocol to be used when terminating or creating TLS
6
+    connections.  You can change the value with the gnocchi_ssl_protocol
7
+    variable.

Loading…
Cancel
Save