public inbox for pbs-devel@lists.proxmox.com
 help / color / mirror / Atom feed
* Re: [pbs-devel] [PATCH proxmox-backup v2 1/3] config: add cipher-suites to NodeConfig
@ 2022-01-05  8:23 Dietmar Maurer
  0 siblings, 0 replies; 3+ messages in thread
From: Dietmar Maurer @ 2022-01-05  8:23 UTC (permalink / raw)
  To: Proxmox Backup Server development discussion, Hannes Laimer

Please can we have a more elaborate error message here?

Or even better, use a schema verify function to do the checks?

 
> +        let mut dummy_acceptor = SslAcceptor::mozilla_intermediate_v5(SslMethod::tls()).unwrap();
> +        if let Some(cipher_suites) = self.cipher_suites_tls3.as_deref() {
> +            dummy_acceptor.set_ciphersuites(cipher_suites)?;
> +        }
> +        if let Some(cipher_suites) = self.cipher_suites_tls2.as_deref() {
> +            dummy_acceptor.set_cipher_list(cipher_suites)?;
> +        }




^ permalink raw reply	[flat|nested] 3+ messages in thread
* Re: [pbs-devel] [PATCH proxmox-backup v2 1/3] config: add cipher-suites to NodeConfig
@ 2022-01-05  8:44 Dietmar Maurer
  0 siblings, 0 replies; 3+ messages in thread
From: Dietmar Maurer @ 2022-01-05  8:44 UTC (permalink / raw)
  To: Proxmox Backup Server development discussion, Hannes Laimer

> On 01/05/2022 9:23 AM Dietmar Maurer <dietmar@proxmox.com> wrote:
> 
>  
> Please can we have a more elaborate error message here?
> 
> Or even better, use a schema verify function to do the checks?

Just noticed that this is a bad idea, because we do not want API types to depend on ssl libs.




^ permalink raw reply	[flat|nested] 3+ messages in thread
* [pbs-devel] [PATCH proxmox-backup v2 0/3] close #3612: allow config of SSL cipher-suites for proxy
@ 2022-01-04 11:48 Hannes Laimer
  2022-01-04 11:48 ` [pbs-devel] [PATCH proxmox-backup v2 1/3] config: add cipher-suites to NodeConfig Hannes Laimer
  0 siblings, 1 reply; 3+ messages in thread
From: Hannes Laimer @ 2022-01-04 11:48 UTC (permalink / raw)
  To: pbs-devel

Cannot be configured in the WebUI, only through proxmox-backup-manager,
api or in the config file directly(not recommended). For changes to take
effect the proxy has to be restarted.

Since the string can be rather long and I assume most of the time the
defaults are used, it is not in the WebUI.

v2:
  - allow setting for TLSv1.3 and TLS <= 1.2 individually

Hannes Laimer (3):
  config: add cipher-suites to NodeConfig
  proxy: use ssl cipher-suites from config if set
  api2: make cipher-suites updatable

 src/api2/node/config.rs         |  8 ++++++++
 src/bin/proxmox-backup-proxy.rs | 10 ++++++++++
 src/config/node.rs              | 24 ++++++++++++++++++++++++
 3 files changed, 42 insertions(+)

-- 
2.30.2





^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2022-01-05  8:44 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2022-01-05  8:23 [pbs-devel] [PATCH proxmox-backup v2 1/3] config: add cipher-suites to NodeConfig Dietmar Maurer
  -- strict thread matches above, loose matches on Subject: below --
2022-01-05  8:44 Dietmar Maurer
2022-01-04 11:48 [pbs-devel] [PATCH proxmox-backup v2 0/3] close #3612: allow config of SSL cipher-suites for proxy Hannes Laimer
2022-01-04 11:48 ` [pbs-devel] [PATCH proxmox-backup v2 1/3] config: add cipher-suites to NodeConfig Hannes Laimer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal