Description
Explicitly enabling weak cipher suites may reduce TLS confidentiality or integrity. RC4, 3DES, and the discouraged CBC suite below have different weaknesses; AES-CBC does not make every implementation vulnerable to the same attack. An attacker may exploit a weak negotiated combination to recover data or compromise a session.
Potential impact
- Disclosure of sensitive data or authentication tokens through weaknesses in negotiated encryption
- Modification of traffic where the selected algorithms or implementation permit an attack
- Reduced protection despite using TLS, potentially failing security requirements
Remediation
- Check the setting's scope:
tls.Config.CipherSuitescontrols TLS 1.0–1.2. TLS 1.3 suites such asTLS_AES_128_GCM_SHA256andTLS_AES_256_GCM_SHA384cannot be configured with it. For explicit TLS 1.2 choices, consulttls.CipherSuites()and official AEAD guidance. - Remove discouraged RC4, 3DES, and CBC suites. Prefer the defaults of a maintained Go release unless an explicit list is needed.
- Set
MinVersionto at leasttls.VersionTLS12, ortls.VersionTLS13where compatible, to exclude older protocols. - Review Go release notes and security guidance for changes to supported and recommended suites.
Examples
Before
go
package main
import (
"crypto/tls"
"net/http"
)
// Before: explicitly select weak cipher suites
func insecureClient() *http.Client {
tr := &http.Transport{
TLSClientConfig: &tls.Config{
// These RC4, 3DES and CBC suites are weak or discouraged
CipherSuites: []uint16{
tls.TLS_RSA_WITH_RC4_128_SHA,
tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA,
tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,
},
MinVersion: tls.VersionTLS10,
},
}
return &http.Client{Transport: tr}
}
After
go
package main
import (
"crypto/tls"
"net/http"
)
// After: use modern cipher suites and TLS versions
func secureClient() *http.Client {
tr := &http.Transport{
TLSClientConfig: &tls.Config{
// Prefer TLS 1.3 where possible; Go maintains default cipher suites
MinVersion: tls.VersionTLS12,
// If required, explicitly choose suitable TLS 1.2 cipher suites
CipherSuites: []uint16{
tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
tls.TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,
tls.TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,
},
},
}
return &http.Client{Transport: tr}
}
Explanation:
- Before: The list explicitly includes
tls.TLS_RSA_WITH_RC4_128_SHA,tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA, andtls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256. RC4 has statistical weaknesses, 3DES has a small block size vulnerable to SWEET32, and CBC risks depend on padding handling and implementation. A TLS 1.0 minimum also permits older protocol combinations. - After:
MinVersion: tls.VersionTLS12excludes TLS 1.0/1.1. The separate suite list selects AEAD algorithms using GCM or CHACHA20-POLY1305 for TLS 1.2, excluding the discouraged suites shown before. Go manages TLS 1.3 suites separately. These choices reduce weak-negotiation risks without replacing certificate validation.