tls: update BoringSSL-FIPS to 20190808.#12114
Conversation
|
CC @envoyproxy/api-shepherds: Your approval is needed for changes made to |
Signed-off-by: Piotr Sikora <[email protected]>
05e8f36 to
91ae3c9
Compare
Signed-off-by: Piotr Sikora <[email protected]>
|
Since the version of BoringSSL that we use in FIPS prior to this PR is from mid-2018, I think it makes sense to backport it to the stable releases in order to enable TLS 1.3 there. Any objections @lambdai @mattklein123 @htuch @lizan? /backport |
htuch
left a comment
There was a problem hiding this comment.
I think backport is OK if you have a motivation from the Istio perspective and want to do the work. I don't think it's strictly needed, i.e. this isn't some security fix or concern with previously shipped functionality.
|
/lgtm v2-freeze |
Signed-off-by: Piotr Sikora <[email protected]> Signed-off-by: Kevin Baichoo <[email protected]>
Signed-off-by: Piotr Sikora <[email protected]> Signed-off-by: scheler <[email protected]>
Signed-off-by: Piotr Sikora [email protected]