Fix SSL/TLS ciphers/options for HAProxy services

Bug #1597061 reported by OpenStack Infra
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Fuel for OpenStack
Confirmed
Medium
Fuel Documentation Team

Bug Description

https://review.openstack.org/335057
Dear bug triager. This bug was created since a commit was marked with DOCIMPACT.

commit 996058caddcd57eed9bfc9d92def923ca68cd7e3
Author: Maksim Malchuk <email address hidden>
Date: Mon Jun 27 23:43:35 2016 +0300

    Fix SSL/TLS ciphers/options for HAProxy services

    * implement the same SSL/TLS ciphers as for Fuel master node (disable
      WEAK DHE ciphers but leave TLSv1 working: LP#1497195
    * remove useless dh_param options because they not needed anymore
    * move the ciphers list to the cluster::haproxy parameters and don't
      repeat this list in the several configuration files (DRY)
    * prepare for an upgrade and move the options list to global settings
      too (DRY) (TODO)
    * ssl_default_ciphers can be changed by end user via hiera

    DocImpact
    Change-Id: I5e5784521641ea3bbe3c4aa40c581f996b268aad
    Closes-Bug: #1594359
    Signed-off-by: Maksim Malchuk <email address hidden>

Changed in fuel:
assignee: nobody → Fuel Documentation Team (fuel-docs)
status: New → Confirmed
importance: Undecided → Medium
milestone: none → 10.0
Dmitry Klenov (dklenov)
tags: added: area-docs
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.