#48785 System wide crypto policy
Closed: wontfix by spichugi. Opened by firstyear.

https://fedoraproject.org/wiki/Changes/CryptoPolicy

We should be able to support the system wide crypto policy in DS. This should be able to apply to the listening tls sockets, and for the available routines to outbound connections.


Metadata Update from @firstyear:
- Issue set to the milestone: FUTURE

Metadata Update from @firstyear:
- Issue assigned to firstyear

Metadata Update from @firstyear:
- Custom field reviewstatus adjusted to None
- Issue assigned to mhonek (was: firstyear)
- Issue close_status updated to: None

Metadata Update from @mhonek:
- Issue tagged with: Security

Suggestions for how to achieve this:
- Deprecate allowweakciphers – default ciphers should be always good.
- Fix logic around tlsversion – use SSL_VersionRangeGet{Default,Supported}, do not force, warn if out of default, and err if out of supported.
- User-requested ciphers – check against default and warn if out of it.

Outbound connections should be fine since it seems we don't set ciphers at all for them (so defaults according to policy apply), and the TLS version min. is inherited from our cn=config sslVersionMin.

Metadata Update from @mreynolds:
- Issue set to the milestone: 1.4.5 (was: FUTURE)

Metadata Update from @mreynolds:
- Issue set to the milestone: 1.4.3 (was: 1.4.5)

389-ds-base is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in 389-ds-base's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/389ds/389-ds-base/issues/1845

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata Update from @spichugi:
- Issue close_status updated to: wontfix
- Issue status updated to: Closed (was: Open)

Metadata