View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0011677 | Taler | deployment and operations | public | 2026-07-25 16:58 | 2026-07-25 16:58 |
| Reporter | Christian Grothoff | Assigned To | Florian Dold | ||
| Priority | normal | Severity | major | Reproducibility | always |
| Status | assigned | Resolution | open | ||
| Platform | i7 | OS | Debian GNU/Linux | OS Version | squeeze |
| Product Version | git (master) | ||||
| Target Version | 1.7 | ||||
| Summary | 0011677: TLS version pinning still disabled | ||||
| Description | See in Ansible: > # FIXME: comment-in later, upgrade fails if we put this immediately, > # we need to run once without, otherwise nginx will see these > # directives twice in different places and the setup script will fail. > # NOTE: remove the above comment AND the commented out lines > # below once spec has been updated once -- then update immediately > # again! > > # ssl_prefer_server_ciphers on; > ## Note: session cache is shared across all services on this server > # ssl_session_cache shared:TLS:10m; > # ssl_dhparam /etc/ssl/private/dhparam.pem; > # ssl_protocols TLSv1.3 TLSv1.2; > # ssl_ciphers 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH'; | ||||
| Tags | BAFIN, compliance, security | ||||
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2026-07-25 16:58 | Christian Grothoff | New Issue | |
| 2026-07-25 16:58 | Christian Grothoff | Status | new => assigned |
| 2026-07-25 16:58 | Christian Grothoff | Assigned To | => Florian Dold |
| 2026-07-25 16:58 | Christian Grothoff | Tag Attached: security | |
| 2026-07-25 16:58 | Christian Grothoff | Tag Attached: comp | |
| 2026-07-25 16:58 | Christian Grothoff | Tag Detached: comp | |
| 2026-07-25 16:58 | Christian Grothoff | Tag Attached: BAFIN | |
| 2026-07-25 16:58 | Christian Grothoff | Tag Attached: compliance |