Review the minimum TLS version in a GCP SSL policy

Review minimum TLS versions and cipher suites together, and associate the policy with the actual proxy.

Description

A policy allowing older TLS versions may not meet current transport-security requirements. Negotiable connections depend on the profile and cipher suites as well as the minimum version.

An SSL policy applies to client connections on its associated target HTTPS or SSL proxy. Configure backend encryption separately.

Potential impact

  • Connections using older protocols may not meet organizational security requirements.
  • Strengthening a policy without checking compatibility can interrupt required clients.

Remediation

  • Set min_tls_version to TLS_1_2 or higher in a supported combination, and review the profile and cipher suites.
  • Associate the policy with the actual target proxy and test that required clients connect while disallowed protocols are rejected.

Examples

These excerpts compare only the minimum version of a CUSTOM policy. Supply at least one supported cipher suite through custom_features separately. Proxy association is also omitted.

Before

hcl
resource "google_compute_ssl_policy" "example" {
  name            = "custom-ssl-policy"
  min_tls_version = "TLS_1_1"
  profile         = "CUSTOM"
}

After

hcl
resource "google_compute_ssl_policy" "example" {
  name            = "custom-ssl-policy"
  min_tls_version = "TLS_1_2"
  profile         = "CUSTOM"
}

Explanation:

  • Before: The minimum is TLS_1_1. Actually permitted protocols also depend on the cipher suites supplied separately.
  • After: The minimum is raised to TLS_1_2. Appropriate cipher selection and actual proxy association still need verification.

References