Description
The policy selected by ssl_policy_id determines the TLS versions and cipher suites a load balancer permits. Specifying an ID alone does not exclude weak settings.
Potential impact
A policy that permits obsolete protocols or weak cipher suites can reduce protection for data in transit.
Remediation
List the policies available to the load balancer and select the ID of one that meets operational requirements. Check the actual permitted settings when relying on a default policy as well.
Examples
These policy-ID excerpts omit certificates and other TLS termination settings. Before using the illustrated ID 4, verify the policy and cryptographic settings it identifies for the load balancer.
Before
hcl
resource "nifcloud_load_balancer" "example" {
load_balancer_name = "example"
instance_port = 443
load_balancer_port = 443
}
After
hcl
resource "nifcloud_load_balancer" "example" {
load_balancer_name = "example"
instance_port = 443
load_balancer_port = 443
ssl_policy_id = "4"
}