Description
An SSL policy that permits older TLS versions may not meet modern transport security requirements. The minimum TLS version, profile and cipher suites jointly determine which connections can actually be negotiated, so review them together.
The policy must be associated with the actual target HTTPS or SSL proxy to take effect. It governs TLS between clients and the load balancer; backend encryption needs separate configuration.
Potential impact
- Connections using permitted older protocols may not meet organizational security requirements.
- Strengthening a policy without checking compatibility can break required client connections.
Remediation
Set min_tls_version to TLS_1_2 or higher in a supported profile and cipher combination. Associate the policy with the actual proxy and test that required clients connect and disallowed protocols are rejected. Verify backend transport encryption separately.
Examples
These excerpts compare SSL policy definitions. Replace policy and project names and the service account JSON file path with actual values. Proxy association is omitted.
Before
- name: create a SSL policy
google.cloud.gcp_compute_ssl_policy:
name: test-ssl-policy
profile: CUSTOM
custom_features:
- TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
project: test_project
auth_kind: serviceaccount
service_account_file: "/tmp/auth.pem"
state: present
- name: create a SSL policy2
google.cloud.gcp_compute_ssl_policy:
name: test-ssl-policy2
profile: CUSTOM
min_tls_version: TLS_1_1
custom_features:
- TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
project: test_project
auth_kind: serviceaccount
service_account_file: "/tmp/auth.pem"
state: present
The minimum version is omitted or set to TLS_1_1. The two listed GCM suites use TLS 1.2, so this setting alone does not establish actual TLS 1.1 connections or weak cipher use.
After
- name: create a SSL policy
google.cloud.gcp_compute_ssl_policy:
name: test-ssl-policy
profile: CUSTOM
min_tls_version: TLS_1_2
custom_features:
- TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
This explicitly sets TLS_1_2 with the same CUSTOM cipher suites. Check policy association and the clients’ actual TLS negotiation.