Update Default Value for Chart defaultSSLPolicy because of Update TLS to version 1.2 or higher
#4055
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Issue
#4054
Description
To ensure compliance with modern security standards and to mitigate vulnerabilities associated with older TLS versions, we need to configure the Application Load Balancer (ALB) to use an SSL policy that enforces TLS 1.2 or higher. This change aligns with industry best practices and AWS recommendations.
Requirements:
Update the ALB's SSL policy to one that supports only TLS 1.2 and TLS 1.3.
Recommended policies include:
ELBSecurityPolicy-TLS13-1-2-2021-06
Verify that the updated policy disables support for deprecated protocols such as TLS 1.0 and TLS 1.1.
Ensure compatibility with all client systems accessing the ALB.
Justification:
Security Compliance: Industry standards such as PCI DSS, NIST, and others mandate the use of secure protocols like TLS 1.2 or higher.
AWS Recommendations: AWS documentation recommends using the latest predefined security policies, such as ELBSecurityPolicy-TLS13-1-2-2021-06, which support TLS 1.3 and are backward-compatible with TLS
Mitigation of Vulnerabilities: Older protocols (TLS 1.0/1.1) are considered insecure and have been deprecated by most modern browsers and operating systems.
https://trendmicro.com/cloudoneconformity/knowledge-base/aws/ELBv2/security-policy.html
Checklist
README.md
, or thedocs
directory)BONUS POINTS checklist: complete for good vibes and maybe prizes?! 🤯