apache / apache/apisix-helm-chart

Remove `DES-CBC3-SHA` from TLS Ciphers

Open
#835 2 comments 1 reaction 0 assignees View on GitHub
enhancement
Dominant language
Go Template
Stars
289
Forks
282
Avg merge
2d 19h
Merged PRs (30d)
4

Description

I've scanned one of my setup lately and nmap is reporting use of unsecure cipher:
```
nmap -Pn -p 443 --script ssl-enum-ciphers my.dev.setup.com
Starting Nmap 7.95 ( https://nmap.org ) at 2025-06-12 15:40 PDT
Nmap scan report for my.dev.setup.com (1.2.3.4)
Host is up (0.69s latency).

PORT STATE SERVICE
443/tcp open https
| ssl-enum-ciphers:
| TLSv1.2:
| ciphers:
| TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (ecdh_x25519) - A
| TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (ecdh_x25519) - A
| TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (ecdh_x25519) - A
| TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (ecdh_x25519) - A
| TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (ecdh_x25519) - A
| TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (ecdh_x25519) - A
| TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (ecdh_x25519) - A
| TLS_RSA_WITH_AES_128_GCM_SHA256 (rsa 2048) - A
| TLS_RSA_WITH_AES_256_GCM_SHA384 (rsa 2048) - A
| TLS_RSA_WITH_AES_128_CBC_SHA256 (rsa 2048) - A
| TLS_RSA_WITH_AES_256_CBC_SHA256 (rsa 2048) - A
| TLS_RSA_WITH_AES_128_CBC_SHA (rsa 2048) - A
| TLS_RSA_WITH_AES_256_CBC_SHA (rsa 2048) - A
| TLS_RSA_WITH_3DES_EDE_CBC_SHA (rsa 2048) - C
| compressors:
| NULL
| cipher preference: server
| warnings:
| 64-bit block cipher 3DES vulnerable to SWEET32 attack
| TLSv1.3:
| ciphers:
| TLS_AKE_WITH_AES_256_GCM_SHA384 (ecdh_x25519) - A
| TLS_AKE_WITH_CHACHA20_POLY1305_SHA256 (ecdh_x25519) - A
| TLS_AKE_WITH_AES_128_GCM_SHA256 (ecdh_x25519) - A
| cipher preference: server
|_ least strength: C
```
Is there any specific reason that ApiSix has to use 3DES? Can this be removed?

I have prepared a PR covering this and also adding easy way to configure list of supported ciphers by ApiSix https://github.com/apache/apisix-helm-chart/pull/834 - maybe this could be merged?

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the current APISIX Helm chart TLS cipher settings and the referenced PR #834, since the issue names no files or tests. Confirm how the chart configures supported ciphers, then verify that DES-CBC3-SHA is removed and the proposed cipher-list configuration works as intended.

Written by the indexing model from the issue text.

Assessment

Tech stack
helm, kubernetes
Domain
devops, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.