Bug #20282

Provide a more secure apache ssl.conf sslciphersuite configuration on by default

Added by Tomer Brisker 3 months ago. Updated 3 months ago.

Status:Closed
Priority:Normal
Assigned To:Tomer Brisker
Category:-
Target version:-
Difficulty: Bugzilla link:1467434
Found in release: Pull request:https://github.com/theforeman/foreman-installer/pull/236, https://github.com/theforeman/foreman-installer/pull/237
Story points-
Velocity based estimate-
Release1.15.3Release relationshipAuto

Description

Set the default ciphesuites for apache to a stronger setting then the default provided by the puppet module.

Associated revisions

Revision 267653fa
Added by Tomer Brisker 3 months ago

Fixes #20282, #14667 - Provide more secure defaults for apache (#236)

This sets the default ciphersuites to the recommended for the time of
writing for the supported servers and browsers. This also disables
TRACE method, which is not a security vulnerability but comes up often
in automated security audits and isn't required for proper functioning
of Foreman.

Revision aea07409
Added by Michael Moll 3 months ago

Refs #20282 - add more ciphers (#237)

The list got cut off in the initial PR.

The JRE coming with Debian/jessie exposed problems with Puppetserver,
delivering reports to Foreman with the original cipher list.

History

#1 Updated by Ewoud Kohl van Wijngaarden 3 months ago

  • Subject changed from Provide a more secure apache ssl.conf sslciphersuite configuration on by default to Provide a more secure apache ssl.conf sslciphersuite configuration on by default
  • Status changed from New to Need more information

We could use the modern cipher suite from https://mozilla.github.io/server-side-tls/ssl-config-generator/ but could you be a bit more specific? The linked bugzilla is not public.

#3 Updated by Tomer Brisker 3 months ago

  • Status changed from Need more information to New

#4 Updated by The Foreman Bot 3 months ago

  • Status changed from New to Ready For Testing
  • Assigned To set to Tomer Brisker
  • Pull request https://github.com/theforeman/foreman-installer/pull/236 added

#5 Updated by Anonymous 3 months ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100

#6 Updated by Eric Helms 3 months ago

  • Release set to 1.15.3

#7 Updated by The Foreman Bot 3 months ago

  • Pull request https://github.com/theforeman/foreman-installer/pull/237 added

Also available in: Atom PDF