consul-k8s icon indicating copy to clipboard operation
consul-k8s copied to clipboard

Consider Configuring `tls_cipher_suites` in the Helm-Chart

Open NodyHub opened this issue 2 years ago • 1 comments

It may be useful to consider using the tls_cipher_suites configuration option in the Helm-Chart. Without configuring this, the default list allows for older/insecure cipher suites to be used.

NodyHub avatar Apr 26 '22 13:04 NodyHub

As we from the product security team recommend in vault (#25, #42, #52), it would also be recommended to configure these parameter on the consul site.

Even is this configuration gets somewhen outdated from go version 1.17, it might take a while to migrate consul up from version 1.13.

NodyHub avatar Apr 27 '22 13:04 NodyHub