Bug 1159356

Summary: puppet: disable SSLv3 support in Puppet
Product: [Fedora] Fedora EPEL Reporter: Vasyl Kaigorodov <vkaigoro>
Component: puppetAssignee: Jeroen van Meeuwen <vanmeeuwen+fedora>
Status: CLOSED WONTFIX QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: epel7CC: ekohlvan, extras-qa, fedora, jose.p.oliveira.oss, k.georgiou, ktdreyer, lzap, mastahnke, mmagr, moses, s, tmz, vanmeeuwen+fedora
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: 1159355 Environment:
Last Closed: 2022-06-12 14:41:59 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1159358, 1159355, 1159360    
Bug Blocks:    

Description Vasyl Kaigorodov 2014-10-31 16:21:36 UTC
+++ This bug was initially created as a clone of Bug #1159355 +++

Upstream has released a new version of Puppet, that disables SSLv3 protocol  negotiation to prevent fallback to the insecure protocol.

http://puppetlabs.com/security/cve/poodle-sslv3-vulnerability

Comment 1 Ewoud Kohl van Wijngaarden 2022-06-12 14:41:59 UTC
Puppet will be retired from EPEL 7.