View Issue Details

IDProjectCategoryView StatusLast Update
0011677Talerdeployment and operationspublic2026-07-25 16:58
ReporterChristian Grothoff Assigned ToFlorian Dold  
PrioritynormalSeveritymajorReproducibilityalways
Status assignedResolutionopen 
Platformi7OSDebian GNU/LinuxOS Versionsqueeze
Product Versiongit (master) 
Target Version1.7 
Summary0011677: TLS version pinning still disabled
DescriptionSee in Ansible:

> # FIXME: comment-in later, upgrade fails if we put this immediately,
> # we need to run once without, otherwise nginx will see these
> # directives twice in different places and the setup script will fail.
> # NOTE: remove the above comment AND the commented out lines
> # below once spec has been updated once -- then update immediately
> # again!
>
> # ssl_prefer_server_ciphers on;
> ## Note: session cache is shared across all services on this server
> # ssl_session_cache shared:TLS:10m;
> # ssl_dhparam /etc/ssl/private/dhparam.pem;
> # ssl_protocols TLSv1.3 TLSv1.2;
> # ssl_ciphers 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH';
TagsBAFIN, compliance, security

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2026-07-25 16:58 Christian Grothoff New Issue
2026-07-25 16:58 Christian Grothoff Status new => assigned
2026-07-25 16:58 Christian Grothoff Assigned To => Florian Dold
2026-07-25 16:58 Christian Grothoff Tag Attached: security
2026-07-25 16:58 Christian Grothoff Tag Attached: comp
2026-07-25 16:58 Christian Grothoff Tag Detached: comp
2026-07-25 16:58 Christian Grothoff Tag Attached: BAFIN
2026-07-25 16:58 Christian Grothoff Tag Attached: compliance