Project

General

Profile

Actions

User story #9502

closed

Drop old protocol and acl for agents

Added by Alexis Mousset over 7 years ago. Updated about 6 years ago.

Status:
Released
Priority:
N/A
Category:
System techniques
Target version:
UX impact:
Suggestion strength:
User visibility:
Effort required:
Name check:
Fix check:
Regression:

Description

  • We only generate key-based acl: improved security (and speed in cf-serverd, because we skip the very unefficient hostname comparison), get rid of all the DNS issues
  • allowlegacyconnects => { } to completely block old protocol
  • Maybe add restriction on used protocols/cipher (allowtlsversion, allowciphers, tls_min_version, tls_ciphers)

Related issues 1 (0 open1 closed)

Related to Rudder - Architecture #10718: Rudder 3.1 agents will not be compatible with Rudder >=4.3RejectedActions
Actions

Also available in: Atom PDF