Skip to content

Commit

Permalink
[Backport 7.63.x] [AGENTRUN-162] Disable X25519Kyber768Draft00 in the…
Browse files Browse the repository at this point in the history
… agent (#34503)

Co-authored-by: Pierre Gimalac <[email protected]>
  • Loading branch information
jeremy-hanna and pgimalac authored Feb 27, 2025
1 parent e908c4d commit d0481fd
Show file tree
Hide file tree
Showing 2 changed files with 20 additions and 0 deletions.
8 changes: 8 additions & 0 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,14 @@ module github.com/DataDog/datadog-agent

go 1.23.0

toolchain go1.23.5

// Disable experimental post-quantum key exchange mechanism X25519Kyber768Draft00
// This was causing errors with AWS Network Firewall
// See https://github.com/DataDog/datadog-agent/issues/34323 for details.
// This will be revisited once we update to 1.24.x
godebug tlskyber=0

// v0.8.0 was tagged long ago, and appared on pkg.go.dev. We do not want any tagged version
// to appear there. The trick to accomplish this is to make a new version (in this case v0.9.0)
// that retracts itself and the previous version.
Expand Down
12 changes: 12 additions & 0 deletions releasenotes/notes/fix-kyber-firewall-1d38f83a241208f7.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
# Each section from every release note are combined when the
# CHANGELOG.rst is rendered. So the text needs to be worded so that
# it does not depend on any information only available in another
# section. This may mean repeating some details, but each section
# must be readable independently of the other.
#
# Each section note must be formatted as reStructuredText.
---
fixes:
- |
Disable the X25519Kyber768Draft00 key exchange mechanism to avoid issues with
firewalls not supporting it, in particular AWS Network Firewall.

0 comments on commit d0481fd

Please sign in to comment.