New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Enable TLS 1.3 default #223
base: master
Are you sure you want to change the base?
Conversation
|
Looks like it doesn't work, but starting the service works. Perhaps it doesn't actually start up and quickly dies. |
|
I updated server.xml with: sslEnabledProtocols="TLSv1.2+TLSv1.3" services are restarted and hammer ping returns all okay. But openssl is not happy: looks like TLS1.3 is still not be enabled on Satellite 6.11, :-) |
|
https://ssl-config.mozilla.org suggests you need Tomcat 8 for this and on EL8 the pki-core module has 7.7.1. |
TLS version 1.3 is the latest TLS version. Now that we've dropped EL7 support this is supported.
|
Rebased now that we're on Java 17. Perhaps that works. |
|
It threw some error within GA and thus did not actually run. |
|
Yes, GH is just broken on/off this week: https://www.githubstatus.com/ |
|
It fails to start up, but our CI doesn't really share any logs of what failed so that's tricky to debug. It does look like it's not as trivial as it would seem. |
|
Latest now this should be testing against is |
TLS version 1.3 is the latest TLS version. Now that we've dropped EL7 support this may be supported. Currently a draft since I don't know if it really does work. If it does, I'll also create a Redmine issue for this.
Came from https://bugzilla.redhat.com/show_bug.cgi?id=2117842