Kubernetes credentials plugin is not FIPS compliant.

      It allows skipping TLS verify which should not be allowed in a FIPS 140-2 environment.

      It can also expose credentials through non TLS connection, which should not be allowed in a FIPS 140-2 environment.

          [JENKINS-73525] Plugin is not FIPS compliant

          Jean-Marc Desprez created issue -
          Jean-Marc Desprez made changes -
          Status Original: Open [ 1 ] New: In Progress [ 3 ]
          Jean-Marc Desprez made changes -
          Status Original: In Progress [ 3 ] New: In Review [ 10005 ]
          Jean-Marc Desprez made changes -
          Remote Link New: This issue links to "Pull request (Web Link)" [ 29835 ]

          Lee added a comment -

          This change appears to have introduced a bug that I've just raised on https://issues.jenkins.io/browse/JENKINS-73610

           

          Lee added a comment - This change appears to have introduced a bug that I've just raised on https://issues.jenkins.io/browse/JENKINS-73610  
          Lee made changes -
          Link New: This issue is blocked by JENKINS-73611 [ JENKINS-73611 ]
          Lee made changes -
          Link Original: This issue is blocked by JENKINS-73611 [ JENKINS-73611 ]
          Lee made changes -
          Link New: This issue causes JENKINS-73610 [ JENKINS-73610 ]
          James Nord made changes -
          Resolution New: Fixed [ 1 ]
          Status Original: In Review [ 10005 ] New: Closed [ 6 ]

            jmdesprez Jean-Marc Desprez
            jmdesprez Jean-Marc Desprez
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: