Bug 1159360

Summary: puppet: disable SSLv3 support in Puppet
Product: Red Hat OpenStack Reporter: Vasyl Kaigorodov <vkaigoro>
Component: puppetAssignee: Martin Magr <mmagr>
Status: CLOSED WONTFIX QA Contact: Jaroslav Henner <jhenner>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: unspecifiedCC: dcleal, extras-qa, fedora, gmollett, jose.p.oliveira.oss, k.georgiou, lzap, mastahnke, mburns, mmagr, moses, slong, srevivo, s, tmz, vanmeeuwen+fedora
Target Milestone: ---Keywords: ZStream
Target Release: 6.0 (Juno)   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: 1159355 Environment:
Last Closed: 2016-11-21 02:26:46 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1159355    
Bug Blocks: 1159358, 1152789, 1159356    

Description Vasyl Kaigorodov 2014-10-31 16:26:05 UTC
+++ This bug was initially created as a clone of Bug #1159355 +++

Upstream has released a new version of Puppet, that disables SSLv3 protocol  negotiation to prevent fallback to the insecure protocol.

http://puppetlabs.com/security/cve/poodle-sslv3-vulnerability

Comment 5 Summer Long 2016-10-13 00:35:00 UTC
Whoa, this is OLD, but looks like it was never initially attached to the flaw (CVE-2014-3566). Fixed in puppet-3.7, so all the RHOSP versions except 10 (which uses 3.8) will need to be updated. I'll create the bugs. Thanks for the heads up.