Enable TLS 1.2 for HTTPS connections for CPS-based fencing with Infoscale 7.4.1 and 8.0

book

Article ID: 100050729

calendar_today

Updated On:

Description

To enable TLS 1.2 for CPS-based fencing

  1. Perform the following tasks on all the server nodes and the client nodes:
    1. Install Infoscale patch.
      • 7.4.1.X install patch 7.4.1.2900
      • 8.0.X install patch 8.0.0.1800
    2. Edit the /etc/vxcps_ssl.properties file to set the value of openSSL.server.requireTLSv1_2 to true.
  2. Restart had on the server nodes.
  3. Restart vxfen on the client nodes.

 

Resolution

You can choose to configure HTTPS connections to use TLS 1.2.

Issue/Introduction

By default, CPS-based fencing uses TLS 1.0 for HTTPS connections.