Actions
Bug #13747
closedwebrick needs option to change SSL ciphers via configuration vs hard coded values
Difficulty:
Triaged:
Bugzilla link:
Pull request:
Description
Cloned from https://bugzilla.redhat.com/show_bug.cgi?id=1282514
Description of problem:
Currently the foreman-proxy piece has hard coded SSL ciphers in the following file:
/usr/share/foreman-proxy/lib/poodles-fix.rb
In order for users to pass certain security audits some Ciphers need to be disabled and currently they only approach is to modify the code, remove the offending cipher, and restart foreman-proxy. This workaround does not survive rpm updates and needs to be moved to a configuration file
Actions