Re: Chrome 117, OpenSSL 1.0.2 and TLSv1.2 problems

2023-10-04 Thread Jered Floyd
This update is in progress. The RPMs are linked here, and if you have a Fedora Project account you can upvote to get this into stable faster: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-a08f6a3e19 --Jered - On Oct 4, 2023, at 11:36 AM, Jered Floyd je...@convivian.com wrote:

Re: Chrome 117, OpenSSL 1.0.2 and TLSv1.2 problems

2023-10-04 Thread Steve Malenfant
FYI - There is a workaround (toggle) to re-enable but not really useful. https://chromestatus.com/feature/4832850040324096 And also found the Chrome roadmap: https://chromestatus.com/roadmap Steve On Wed, Oct 4, 2023 at 6:37 AM Jered Floyd wrote: > > Thanks, Steve -- this is almost certainly

Re: Chrome 117, OpenSSL 1.0.2 and TLSv1.2 problems

2023-10-04 Thread Jered Floyd
Thanks, Steve -- this is almost certainly the simplest answer since trafficserver is in EPEL so the EPEL dependency won't be an issue. I'll push a build to epel-testing later today. If there are any other RHEL/CentOS 7 users out there on the list, please let me know as 3 up votes will let us

Re: Chrome 117, OpenSSL 1.0.2 and TLSv1.2 problems

2023-10-03 Thread Steve Malenfant
FYI - I recompiled ATS 8.1.x with OpenSSL 1.1 (EPEL) and that worked for us. (Centos 7) On Tue, Oct 3, 2023 at 6:33 AM Jered Floyd wrote: > > Chrome 117 has just rolled out denial of SHA1 signature algorithms (for > header signing -- not ciphers which have already been removed) and now > Chome o

Chrome 117, OpenSSL 1.0.2 and TLSv1.2 problems

2023-10-03 Thread Jered Floyd
Chrome 117 has just rolled out denial of SHA1 signature algorithms (for header signing -- not ciphers which have already been removed) and now Chome on any platform is unable to connect to trafficserver 9.2.2 on RHEL 7. I'm the Fedora/RHEL package maintainer so this is my problem, but before I