Review the NIFCLOUD load balancer TLS policy name

Choose a policy that excludes obsolete TLS versions and weak cipher suites.

Description

A load balancer TLS policy determines the permitted protocol versions and cipher suites. Older or default policies may include settings that should no longer be used.

Potential impact

Allowing weak TLS settings can reduce protection for data in transit.

Remediation

Check the policy contents and set ssl_policy_name to a policy that meets operational requirements. Verify required client connections after the change.

Examples

These policy excerpts omit certificates and other TLS termination settings. Standard Ciphers D ver1 permits only TLS 1.2, but its cipher suites must also meet operational requirements.

Before

hcl
resource "nifcloud_load_balancer" "example" {
  load_balancer_name = "example"
  instance_port      = 443
  load_balancer_port = 443
}

After

hcl
resource "nifcloud_load_balancer" "example" {
  load_balancer_name = "example"
  instance_port      = 443
  load_balancer_port = 443
  ssl_policy_name    = "Standard Ciphers D ver1"
}

References