envoyproxy / envoyproxy/envoy

Remove SHA-1 cipher suites from the defaults on the server-side

Open
#5,400 0 comments 0 reactions 0 assignees View on GitHub
area/tls help wanted
Dominant language
C++
Stars
28.9k
Forks
5.6k
Avg merge
1d 22h
Merged PRs (30d)
430

Description

This is the intent to remove remaining SHA-1 cipher suites (i.e. `ECDHE-ECDSA-AES128-SHA`, `ECDHE-RSA-AES128-SHA`, `ECDHE-ECDSA-AES256-SHA` and `ECDHE-RSA-AES256-SHA`) from the default cipher suites on the server-side.

This change will affect your deployment if it's using default cipher suites (i.e. not configuring `cipher_suites`) and it's accepting incoming connections using those cipher suites:
```
$ curl -s localhost:9901/stats | grep -E "^listener.*.ssl.ciphers..*SHA:"
listener.

.ssl.ciphers.ECDHE-ECDSA-AES128-SHA: 1
listener.
.ssl.ciphers.ECDHE-ECDSA-AES256-SHA: 1
listener.
.ssl.ciphers.ECDHE-RSA-AES128-SHA: 1
listener.
.ssl.ciphers.ECDHE-RSA-AES256-SHA: 1
```
(This works only with Envoy v1.9.0 and newer)

ETA: 1.15 (i.e. ~late 2020)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.