Skip to content

Check that we conform to the OpenADR 3.1 TLS guidance #289

@bjorn3

Description

@bjorn3
  • Only allow tls 1.2+ (I think already implicitly done due to rustls usage, which only supports tls 1.2+).
  • Must not use unencrypted http.
  • Have a configuration option to allow self-signed certificates (optional. if we don't have such an option, self-signed certificates should be denied, even if the spec does not require this)

Metadata

Metadata

Assignees

No one assigned

    Labels

    OADR 3.1Related to the OpenADR 3.1 release

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions