[Yahoo-eng-team] [Bug 1771773] Re: Ssl2/3 should not be used for secure VNC access

2018-08-10 Thread Daniel Berrange
Sorry, I didn't mean to suggest we should abandon the change/bug, as not all distros have crypto policy support systemwide. Rather, that we should 1. make sure the out of the box behaviour is to honour openssl defaults 2. provide a nova.conf setting for the protocol version, which allows an

[Yahoo-eng-team] [Bug 1771773] Re: Ssl2/3 should not be used for secure VNC access

2018-08-09 Thread melanie witt
I'm going to close out this bug based on input from Daniel Berrange from the patch review: "IMHO hardcoding a specific TLS version is pretty undesirable. There is active work to enable TLS 1.3 in all crypto libraries in the very near future, so we really want choice of version to be configurable,