Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security: report warning when TLS version is below 1.2 #350

Merged
merged 2 commits into from
Aug 30, 2023

Conversation

djshow832
Copy link
Collaborator

What problem does this PR solve?

Issue Number: close #337

Problem Summary:
TiDB reports warnings when TLS version is below 1.2: https://github.com/pingcap/tidb/blob/master/util/misc.go#L499
But TiProxy doesn't: https://github.com/pingcap/TiProxy/blob/main/lib/config/proxy.go#L114

TiProxy can add the warning to keep consistency.

What is changed and how it works:

  • Move parsing TLS version from config to security because it can import logger.
  • Report warning if necessary.

Check List

Tests

  • Unit test
  • Integration test
  • Manual test (add detailed scripts or steps below)
  • No code

Notable changes

  • Has configuration change
  • Has HTTP API interfaces change
  • Has tiproxyctl change
  • Other user behavior changes

Release note

Please refer to Release Notes Language Style Guide to write a quality release note.

None

@ti-chi-bot ti-chi-bot bot requested review from bb7133 and xhebox August 30, 2023 08:44
@ti-chi-bot ti-chi-bot bot added the size/L label Aug 30, 2023
@ti-chi-bot
Copy link

ti-chi-bot bot commented Aug 30, 2023

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: xhebox

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@ti-chi-bot
Copy link

ti-chi-bot bot commented Aug 30, 2023

[LGTM Timeline notifier]

Timeline:

  • 2023-08-30 08:59:54.947101293 +0000 UTC m=+1917559.496117277: ☑️ agreed by xhebox.

@ti-chi-bot ti-chi-bot bot merged commit 7f0eed6 into pingcap:main Aug 30, 2023
@djshow832 djshow832 deleted the tls_warn branch August 30, 2023 09:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Report warning when TLS version is below 1.2
2 participants