Description
A GCP SSL policy controls TLS settings on the client-facing connection of an associated load balancer. Allowing older TLS versions may fail current transport security requirements. The permitted cipher suites depend on the profile as well as minTlsVersion.
Potential impact
- Connections using older protocols may not meet your security requirements.
- Tightening a policy without compatibility testing can interrupt required client connections.
Remediation
Set minTlsVersion to TLS_1_2 or later in a supported combination, and review the profile and cipher suites. Attach the policy to the actual target proxy, then test that required clients connect and prohibited protocols are rejected.
Examples
These excerpts compare only the minimum TLS version. The target proxy attachment is omitted, and backend encryption must be configured separately.
Before
resources:
example:
type: gcp:compute:SSLPolicy
properties:
minTlsVersion: TLS_1_1
After
resources:
example:
type: gcp:compute:SSLPolicy
properties:
minTlsVersion: TLS_1_2
The minimum version increases from TLS 1.1 to TLS 1.2. This alone neither selects specific cipher suites nor applies the policy to every service.