Uploaded image for project: 'Hue (READ ONLY)'
  1. Hue (READ ONLY)
  2. HUE-9106

[core] Add SSL_NO_RENEGOCIATION option

    Details

    • Type: Task
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 4.6.0
    • Fix Version/s: 4.7.0
    • Component/s: core.api
    • Labels:
      None

      Description

      ssl.OP_NO_RENEGOTIATION

      Disable all renegotiation in TLSv1.2 and earlier. Do not send HelloRequest messages, and ignore renegotiation requests via ClientHello.

      This option is only available with OpenSSL 1.1.0h and later.
      New in version 3.7.

      This is to handle vulnerability in ssl renegotiation which is disabled by default in TLSv1.3. It's not clear if openSSL is vulnerable: 

        Attachments

          Activity

            People

            • Assignee:
              jgauthier Jean Francois Desjeans Gauthier
              Reporter:
              jgauthier Jean Francois Desjeans Gauthier
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: