tls: add tls v1.3 configuration option#1577
Merged
BareosBot merged 15 commits intobareos:masterfrom Oct 27, 2023
Merged
Conversation
5f1312c to
cd9a260
Compare
pstorz
requested changes
Oct 23, 2023
Member
pstorz
left a comment
There was a problem hiding this comment.
Is it possible to test kTLS somehow?
I think would make sense to at least have a test that enables kTLS and checks if it is enabled somehow.
sebsura
commented
Oct 23, 2023
sebsura
commented
Oct 23, 2023
pstorz
requested changes
Oct 24, 2023
Member
pstorz
left a comment
There was a problem hiding this comment.
Good work! Please see comments.
fc058ea to
69e458a
Compare
effcb91 to
3eb88db
Compare
pstorz
approved these changes
Oct 27, 2023
0976e34 to
0208820
Compare
0208820 to
cffc621
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Thank you for contributing to the Bareos Project!
Adds a simple configuration option that allows the user to select which tls cipher he wishes to use.
One caveat is that currently only SHA256 ciphers are supported; this in effect means that currently
the cipher
TLS_AES_256_GCM_SHA384is not supported.This PR also adds a config option to make bareos tell openssl to use ktls if it can.
Please check
If you have any questions or problems, please give a comment in the PR.
Helpful documentation and best practices
Checklist for the reviewer of the PR (will be processed by the Bareos team)
Make sure you check/merge the PR using
devtools/pr-toolto have some simple automated checks run and a proper changelog record added.General
Source code quality
Tests