Ticket was cloned from Red Hat Bugzilla (product Red Hat Enterprise Linux 7): Bug 1711172
Problem: -> Insights reports the following "Decreased security in httpd when using deprecated TLS protocol version (PCI DSS)" # grep NSSProtocol /etc/httpd/conf.d/nss.conf NSSProtocol TLSv1.0,TLSv1.1,TLSv1.2 Question? Why we still have the weak protocols still enabled and then have Insights complain about this. Action Item: - Use latest NSS version available.
Metadata Update from @frenaud: - Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1711172
Note: this issue only applies to FreeIPA versions using mod_nss (mod_ssl is used from 4.7.0+).
Metadata Update from @frenaud: - Issue assigned to frenaud
Metadata Update from @frenaud: - Custom field on_review adjusted to https://github.com/freeipa/freeipa/pull/3351
ipa-4-6:
Metadata Update from @frenaud: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)
master:
ipa-4-7:
ipa-4-8: