How to disable tls 1.0 & 1.1 of a route in OpenShift Online Pro

Viewed 971

I am using OpenShift Online Pro account , I deployed a web application using apache httpd2.4 server and I created a route with domain I purchased from AWS.

Then I add SSL certificates using letsencrypt , now when I test this router I can see tls 1.0 & 1.1 are deprecated and some list of weak ciphers and I want to remove them from this router.

How can I disable this 2 versions and remove weak Ciphers ?

Any help could be appreaciated!

1 Answers

In OpenShift, TLS ciphers can only be enabled / disabled on a Router basis (see documentation). This means for OpenShift Online this is most likely not possible, although I would recommend to ask Support about it.

A workaround would be to use a "passthrough" Route and to terminate TLS in your container. That way you can control what TLS versions your application / webserver is serving.

Related