Browse Source

Force force-tlsv12 only

Secure by default

Change-Id: I70007af94bfd5e482662ab72d25bf090cf5d0834
Matthew Thode 4 months ago
parent
commit
547d7f91be
No account linked to committer's email address
2 changed files with 8 additions and 1 deletions
  1. 1
    1
      defaults/main.yml
  2. 7
    0
      releasenotes/notes/tls12-only-a22d5f3f8198617f.yaml

+ 1
- 1
defaults/main.yml View File

@@ -68,7 +68,7 @@ haproxy_ssl_pem: /etc/ssl/private/haproxy.pem
68 68
 haproxy_ssl_ca_cert: /etc/ssl/certs/haproxy-ca.pem
69 69
 haproxy_ssl_self_signed_subject: "/C=US/ST=Texas/L=San Antonio/O=IT/CN={{ external_lb_vip_address }}/subjectAltName=IP.1={{ external_lb_vip_address }}"
70 70
 haproxy_ssl_cipher_suite: "{{ ssl_cipher_suite | default('ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:RSA+AESGCM:RSA+AES:!aNULL:!MD5:!DSS') }}"
71
-haproxy_ssl_bind_options: "no-sslv3"
71
+haproxy_ssl_bind_options: "force-tlsv12"
72 72
 
73 73
 # hatop extra package URL and checksum
74 74
 haproxy_hatop_download_url: "https://storage.googleapis.com/google-code-archive-downloads/v2/code.google.com/hatop/hatop-0.7.7.tar.gz"

+ 7
- 0
releasenotes/notes/tls12-only-a22d5f3f8198617f.yaml View File

@@ -0,0 +1,7 @@
1
+---
2
+security:
3
+  - |
4
+    The default TLS version has been set to force-tlsv12.  This only allows
5
+    version 1.2 of the protocol to be used when terminating or creating TLS
6
+    connections.  You can change the value with the haproxy_ssl_bind_options
7
+    variable.

Loading…
Cancel
Save