Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1778250

Summary: RHV metric store allows lower versions of TLS with no way to configure which versions should be allowed.
Product: Red Hat Enterprise Virtualization Manager Reporter: Frank DeLorey <fdelorey>
Component: ovirt-engine-metricsAssignee: Shirly Radco <sradco>
Status: CLOSED WONTFIX QA Contact: Lucie Leistnerova <lleistne>
Severity: high Docs Contact:
Priority: unspecified    
Version: 4.3.5CC: mkalinin, rmeggins, sradco
Target Milestone: ---Keywords: Security
Target Release: ---Flags: lsvaty: testing_plan_complete-
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 1778856 (view as bug list) Environment:
Last Closed: 2020-06-18 13:42:25 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: Metrics RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Frank DeLorey 2019-11-29 15:39:50 UTC
Description of problem:
Security scan of port 443 for the metrics store reports: TLS Version 1.1 Protocol Detection: The remote service encrypts traffic using an older version of TLS.

Version-Release number of selected component (if applicable):

RHV 4.3.5

How reproducible:

Every time.

Steps to Reproduce:
1.Install metrics store on RHV
2.Run a security scan

Actual results:

Security scan report metric store is allowing older TLS versions

Expected results:

We should be using TLS 1.2 or make it configurable for customers required to eliminate TLS 1.1

Additional info:

It appears this is configurable on Kibana however I cannot find a way to do this with our current installation method or how to change it after installation.