]> git-server-git.apps.pok.os.sepia.ceph.com Git - ceph.git/commit
rgw/beast: add ssl_ciphersuites option for tls 1.3 69178/head
authorCasey Bodley <cbodley@redhat.com>
Fri, 15 May 2026 14:40:50 +0000 (10:40 -0400)
committerCasey Bodley <cbodley@redhat.com>
Fri, 29 May 2026 18:44:28 +0000 (14:44 -0400)
commitd8daca895a22d9a0200c99b886d214d8081384df
tree1597d2ff36f8a0effb1aecafb04e95f57c86939c
parent965ff53f375521760d11f744cd7fe39d6e270271
rgw/beast: add ssl_ciphersuites option for tls 1.3

the existing ssl_ciphers option is passed to `SSL_CTX_set_cipher_list()`
which only applies to "TLSv1.2 and below". there's a separate
`SSL_CTX_set_ciphersuites()` for TLSv1.3

because the frontend's default configuration for `ssl_options` accepts
both 1.2 and 1.3, users may need to specify ciphers for each. that's why
`ssl_ciphersuites` is introduced as a separate option

Fixes: https://tracker.ceph.com/issues/76578
Signed-off-by: Casey Bodley <cbodley@redhat.com>
(cherry picked from commit c62f537f2c99513ef04595c748d392e9da36a7fd)

Conflicts:
doc/radosgw/frontends.rst  openssl -> OpenSSL
src/rgw/rgw_asio_frontend.cc  no tls_groups on tentacle
doc/radosgw/frontends.rst
src/rgw/rgw_asio_frontend.cc