Review the minimum TLS version in a GCP SSL policy

Review the minimum TLS version and cipher suites, and apply the policy to the actual target proxy.

Description

A GCP SSL policy controls TLS settings on the client-facing connection of an associated load balancer. Allowing older TLS versions may fail current transport security requirements. The permitted cipher suites depend on the profile as well as minTlsVersion.

Potential impact

  • Connections using older protocols may not meet your security requirements.
  • Tightening a policy without compatibility testing can interrupt required client connections.

Remediation

Set minTlsVersion to TLS_1_2 or later in a supported combination, and review the profile and cipher suites. Attach the policy to the actual target proxy, then test that required clients connect and prohibited protocols are rejected.

Examples

These excerpts compare only the minimum TLS version. The target proxy attachment is omitted, and backend encryption must be configured separately.

Before

yaml
resources:
  example:
    type: gcp:compute:SSLPolicy
    properties:
      minTlsVersion: TLS_1_1

After

yaml
resources:
  example:
    type: gcp:compute:SSLPolicy
    properties:
      minTlsVersion: TLS_1_2

The minimum version increases from TLS 1.1 to TLS 1.2. This alone neither selects specific cipher suites nor applies the policy to every service.

References