#51061 Issue 51060 - unable to set sslVersionMin to TLS1.0
Closed by spichugi. Opened by mreynolds.
mreynolds/389-ds-base sslminver  into  master

Download 51061.patch

Description:

When processing the "sslVersionMin" attribute we were incorrectly setting it to TLS1.2 (current default level)

https://pagure.io/389-ds-base/issue/51060

Does this leave the max default to 1.2?

Does this leave the max default to 1.2?

Yes, this change only impacts the ssl version range if it is explicitly set. If you don't set it, it defaults to the system crypto policy. So for me on Fedora 31 it defaults to 1.2 for both the min and the max. This bug was that if I set the min to 1.0, the server overwrote it when it should not have.

Cool, in that case ack from me!

rebased onto 3548738f9df0ab7a2df009def81a6fba86b32921

Pull-Request has been merged by mreynolds

389-ds-base is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in 389-ds-base's github repository.

This pull request has been cloned to Github as issue and is available here:
- https://github.com/389ds/389-ds-base/issues/4114

If you want to continue to work on the PR, please navigate to the github issue,
download the patch from the attachments and file a new pull request.

Thank you for understanding. We apologize for all inconvenience.

Pull-Request has been closed by spichugi

Metadata