Skip to content

security: update Ingress default ssl policy ELBSecurityPolicy-TLS13-1-2-2021-06 #9314

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 3 commits into
base: dev
Choose a base branch
from

Conversation

ayruslore
Copy link
Collaborator

@ayruslore ayruslore commented Apr 29, 2025

updates the default ssl policy from ELBSecurityPolicy-TLS-1-2-2017-01 to ELBSecurityPolicy-TLS13-1-2-2021-06 for ingress

Outdated ssl-policy can lead to low level attacks like MitM to break TLS connections. Also TLS ranking tools show us not to be best in class, so we should take care to make it best in class.

updates the default ssl policy from ELBSecurityPolicy-TLS-1-2-2017-01 to ELBSecurityPolicy-TLS13-1-2-2021-06

Signed-off-by: speruri <[email protected]>
@ayruslore ayruslore added the minor Minor changes, e.g. low risk config updates, changes that do not introduce a new API call. label Apr 29, 2025
@ayruslore ayruslore changed the title security: update default ssl policy ELBSecurityPolicy-TLS13-1-2-2021-06 security: update Ingress default ssl policy ELBSecurityPolicy-TLS13-1-2-2021-06 May 5, 2025
@AlexanderYastrebov
Copy link
Member

👍

1 similar comment
@ayruslore
Copy link
Collaborator Author

👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
minor Minor changes, e.g. low risk config updates, changes that do not introduce a new API call.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants