Description
A policy allowing older TLS versions may not meet current transport-security requirements. Negotiable connections depend on the profile and cipher suites as well as the minimum version.
An SSL policy applies to client connections on its associated target HTTPS or SSL proxy. Configure backend encryption separately.
Potential impact
- Connections using older protocols may not meet organizational security requirements.
- Strengthening a policy without checking compatibility can interrupt required clients.
Remediation
- Set
min_tls_versiontoTLS_1_2or higher in a supported combination, and review the profile and cipher suites. - Associate the policy with the actual target proxy and test that required clients connect while disallowed protocols are rejected.
Examples
These excerpts compare only the minimum version of a CUSTOM policy. Supply at least one supported cipher suite through custom_features separately. Proxy association is also omitted.
Before
hcl
resource "google_compute_ssl_policy" "example" {
name = "custom-ssl-policy"
min_tls_version = "TLS_1_1"
profile = "CUSTOM"
}
After
hcl
resource "google_compute_ssl_policy" "example" {
name = "custom-ssl-policy"
min_tls_version = "TLS_1_2"
profile = "CUSTOM"
}
Explanation:
- Before: The minimum is TLS_1_1. Actually permitted protocols also depend on the cipher suites supplied separately.
- After: The minimum is raised to TLS_1_2. Appropriate cipher selection and actual proxy association still need verification.