tls: update BoringSSL-FIPS to 20190808.#12114
Conversation
|
CC @envoyproxy/api-shepherds: Your approval is needed for changes made to |
Signed-off-by: Piotr Sikora <piotrsikora@google.com>
05e8f36 to
91ae3c9
Compare
Signed-off-by: Piotr Sikora <piotrsikora@google.com>
|
Since the version of BoringSSL that we use in FIPS prior to this PR is from mid-2018, I think it makes sense to backport it to the stable releases in order to enable TLS 1.3 there. Any objections @lambdai @mattklein123 @htuch @lizan? /backport |
htuch
left a comment
There was a problem hiding this comment.
I think backport is OK if you have a motivation from the Istio perspective and want to do the work. I don't think it's strictly needed, i.e. this isn't some security fix or concern with previously shipped functionality.
|
/lgtm v2-freeze |
Signed-off-by: Piotr Sikora <piotrsikora@google.com> Signed-off-by: Kevin Baichoo <kbaichoo@google.com>
Signed-off-by: Piotr Sikora <piotrsikora@google.com> Signed-off-by: scheler <santosh.cheler@appdynamics.com>
Signed-off-by: Piotr Sikora piotrsikora@google.com