Review the NIFCLOUD load balancer TLS policy ID

Check the TLS settings selected by the policy ID.

Description

The policy selected by ssl_policy_id determines the TLS versions and cipher suites a load balancer permits. Specifying an ID alone does not exclude weak settings.

Potential impact

A policy that permits obsolete protocols or weak cipher suites can reduce protection for data in transit.

Remediation

List the policies available to the load balancer and select the ID of one that meets operational requirements. Check the actual permitted settings when relying on a default policy as well.

Examples

These policy-ID excerpts omit certificates and other TLS termination settings. Before using the illustrated ID 4, verify the policy and cryptographic settings it identifies for the load balancer.

Before

hcl
resource "nifcloud_load_balancer" "example" {
  load_balancer_name = "example"
  instance_port      = 443
  load_balancer_port = 443
}

After

hcl
resource "nifcloud_load_balancer" "example" {
  load_balancer_name = "example"
  instance_port      = 443
  load_balancer_port = 443
  ssl_policy_id      = "4"
}

References