Skip to content
GitLab
    • GitLab: the DevOps platform
    • Explore GitLab
    • Install GitLab
    • How GitLab compares
    • Get started
    • GitLab docs
    • GitLab Learn
  • Pricing
  • Talk to an expert
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
    • Switch to GitLab Next
    Projects Groups Snippets
  • Sign up now
  • Login
  • Sign in / Register
  • Aegir HTTPS Aegir HTTPS
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 0
    • Issues 0
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 1
    • Merge requests 1
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • AegirAegir
  • Aegir HTTPSAegir HTTPS
  • Issues
  • #38
Closed
Open
Issue created May 18, 2017 by Jon Pugh@jonpughOwner

Secure Sites do not pass security scanning software.

I am setting up hosting_https for a client, successfully setup a LetsEncrypt cert, but a security scan by "IBM Security AppScan" still throws issues.

I'm attaching the full report, but the main issues appear to be the old cipher support (according to my client's security person, this is the main problem.)

  • Deprecated SSL Version is Supported 1
  • RC4 cipher suites were detected 1
  • SHA-1 cipher suites were detected 1
  • Weak SSL Cipher Suites are Supported 1

Full Security Report (pdf)

Edited May 18, 2017 by Jon Pugh
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
Time tracking