-
Notifications
You must be signed in to change notification settings - Fork 4.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Prevent POODLE vulnerability in HAProxy router #7638
Conversation
Rebased onto master. |
@knobunc Needs review. |
After rebasing, only POODLE needed to be handled. |
HAProxy 1.5.14 is now available and used by the router image.
d51939b
to
be9c4de
Compare
Rebased onto master again. It probably wasn't necessary but I did it anyway! |
@knobunc bump |
@pweil- @smarterclayton -- Do we care about any web browsers that can't speak SSLv3? |
I believe the major browsers disabled it at the end of 2014. IMO if we aren't going to break a bunch of folks it seems safest to disable it in haproxy too, folks still have the option to turn it back on. |
I agree - we should be regularly updating to have a secure router ootb.
However, any change to the support ciphers / suites should be a release
note. Also, we should update the "secure settings comment" alongside it.
…On Tue, Feb 7, 2017 at 1:44 PM, Paul Weil ***@***.***> wrote:
Do we care about any web browsers that can't speak SSLv3
I believe the major browsers disabled it at the end of 2014. IMO if we
aren't going to break a bunch of folks it seems safest to disable it in
haproxy too, folks still have the option to turn it back on.
—
You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
<#7638 (comment)>,
or mute the thread
<https://github.com/notifications/unsubscribe-auth/ABG_p0SSpAtr_Oftwv0D1ZHVHQoC-KuDks5raLuIgaJpZM4HjJ2l>
.
|
@openshift/networking FYI [merge] |
@smarterclayton how do we get this into the release notes? |
Evaluated for origin merge up to be9c4de |
continuous-integration/openshift-jenkins/merge SUCCESS (https://ci.openshift.redhat.com/jenkins/job/merge_pull_request_origin/931/) (Base Commit: 596d795) (Image: devenv-rhel7_6331) |
This deals with a few TODO items in some of the images.