lp://staging/~danilo/charm-haproxy/ssl-default-bind-options
- Get this branch:
- bzr branch lp://staging/~danilo/charm-haproxy/ssl-default-bind-options
Branch merges
- Free Ekanayaka (community): Approve
- Adam Collard (community): Approve
-
Diff: 77 lines (+45/-0)3 files modifiedconfig.yaml (+6/-0)
hooks/hooks.py (+3/-0)
hooks/tests/test_helpers.py (+36/-0)
Branch information
Recent revisions
- 105. By Данило Шеган
-
Introduce global_
default_ bind_options config option to allow disabling/forcing SSL protocols. - 99. By Kevin W Monroe
-
[verterok, r=admcleod, a=kwmonroe] restart rsyslog if haproxy config changes; minor updates to tests
- 98. By Chris Glass
-
Merge lp:~tribaal/charms/trusty/haproxy/longer-openssl-selfsigned [a=tribaal] [r=dpb]
Make the self-signed SSL certificate last for 3650 days instead of the default of 30 days.
This mirrors what the apache charm does. - 97. By Chris Glass
-
Merge lp:~free.ekanayaka/charms/trusty/haproxy/no-sslv3 [a=free.ekanayaka] [r=tribaal]
Disable SSL v3 to prevent POODLE attacks when SSL is enabled.
- 96. By Chris Glass
-
Merge lp:~free.ekanayaka/charms/trusty/haproxy/ciphers-support [a=free.ekanayaka] [r=tribaal]
Add a config option to specify what ciphers to use when SSL is enabled.
Default to a sane selection of ciphers, in particular disallowing RC4 and null encryption.
Branch metadata
- Branch format:
- Branch format 7
- Repository format:
- Bazaar repository format 2a (needs bzr 1.16 or later)
- Stacked on:
- lp://staging/charm-haproxy