Description
A load balancer TLS policy determines the permitted protocol versions and cipher suites. Older or default policies may include settings that should no longer be used.
Potential impact
Allowing weak TLS settings can reduce protection for data in transit.
Remediation
Check the policy contents and set ssl_policy_name to a policy that meets operational requirements. Verify required client connections after the change.
Examples
These policy excerpts omit certificates and other TLS termination settings. Standard Ciphers D ver1 permits only TLS 1.2, but its cipher suites must also meet operational requirements.
Before
hcl
resource "nifcloud_load_balancer" "example" {
load_balancer_name = "example"
instance_port = 443
load_balancer_port = 443
}
After
hcl
resource "nifcloud_load_balancer" "example" {
load_balancer_name = "example"
instance_port = 443
load_balancer_port = 443
ssl_policy_name = "Standard Ciphers D ver1"
}