Remove SHA-1 cipher suites from the defaults on the server-side
Open
area/tls
help wanted
- Dominant language
- C++
- Stars
- 28.9k
- Forks
- 5.6k
- Avg merge
- 1d 22h
- Merged PRs (30d)
- 430
Description
This is the intent to remove remaining SHA-1 cipher suites (i.e. `ECDHE-ECDSA-AES128-SHA`, `ECDHE-RSA-AES128-SHA`, `ECDHE-ECDSA-AES256-SHA` and `ECDHE-RSA-AES256-SHA`) from the default cipher suites on the server-side.
This change will affect your deployment if it's using default cipher suites (i.e. not configuring `cipher_suites`) and it's accepting incoming connections using those cipher suites:
```
$ curl -s localhost:9901/stats | grep -E "^listener.*.ssl.ciphers..*SHA:"
listener.
listener..ssl.ciphers.ECDHE-ECDSA-AES256-SHA: 1
listener..ssl.ciphers.ECDHE-RSA-AES128-SHA: 1
listener..ssl.ciphers.ECDHE-RSA-AES256-SHA: 1
```
(This works only with Envoy v1.9.0 and newer)
ETA: 1.15 (i.e. ~late 2020)
Contributor guide
Assessment
This issue has not been assessed yet.