Update cipher suite list and instructions for configuring TLS protocols
Nobody has claimed this yet.
- Dominant language
- CSS
- Stars
- 99
- Forks
- 708
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 22
Description
Description
The current documentation for Disabling weak cipher[1] in WSO2 API Manager points to an outdated site[2]. Additionally, the list of ciphers needs to be revised according to the latest OWASP recommendations.
Refer to the comments:
https://github.com/wso2-enterprise/wso2-apim-internal/issues/11173#issuecomment-3330678973
https://github.com/wso2-enterprise/wso2-apim-internal/issues/11173#issuecomment-3337904705
[1] https://apim.docs.wso2.com/en/latest/install-and-setup/setup/security/configuring-transport-level-security/#disabling-weak-ciphers
[2] https://wso2docs.atlassian.net/wiki/spaces
Suggested Fix
No response
Version(s)
APIM 4.5.0
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the “Disabling weak ciphers” section in the configuring transport-level-security documentation linked in the issue, then review the two referenced comments for the intended updates. Replace the outdated reference, revise the cipher list according to the stated recommendations, and update the TLS configuration instructions so the page reflects APIM 4.5.0.
Written by the indexing model from the issue text.
Assessment
- Domain
- api, documentation, security
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100