mirror of
https://github.com/intel/intel-device-plugins-for-kubernetes.git
synced 2025-06-03 03:59:37 +00:00
tls: limit version to 1.2 only and selected ciphers
Signed-off-by: Tuomas Katila <tuomas.katila@intel.com>
This commit is contained in:
parent
333d6369db
commit
1a13dcd3e2
@ -55,7 +55,14 @@ func main() {
|
|||||||
ctrl.SetLogger(textlogger.NewLogger(tlConf))
|
ctrl.SetLogger(textlogger.NewLogger(tlConf))
|
||||||
|
|
||||||
tlsCfgFunc := func(cfg *tls.Config) {
|
tlsCfgFunc := func(cfg *tls.Config) {
|
||||||
cfg.MinVersion = tls.VersionTLS13
|
cfg.MinVersion = tls.VersionTLS12
|
||||||
|
cfg.MaxVersion = tls.VersionTLS12
|
||||||
|
cfg.CipherSuites = []uint16{
|
||||||
|
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
|
||||||
|
tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
|
||||||
|
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
|
||||||
|
tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
webhookOptions := webhook.Options{
|
webhookOptions := webhook.Options{
|
||||||
|
@ -135,7 +135,14 @@ func main() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
tlsCfgFunc := func(cfg *tls.Config) {
|
tlsCfgFunc := func(cfg *tls.Config) {
|
||||||
cfg.MinVersion = tls.VersionTLS13
|
cfg.MinVersion = tls.VersionTLS12
|
||||||
|
cfg.MaxVersion = tls.VersionTLS12
|
||||||
|
cfg.CipherSuites = []uint16{
|
||||||
|
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
|
||||||
|
tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
|
||||||
|
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
|
||||||
|
tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
webhookOptions := webhook.Options{
|
webhookOptions := webhook.Options{
|
||||||
|
@ -37,7 +37,14 @@ func main() {
|
|||||||
ctrl.SetLogger(textlogger.NewLogger(tlConf))
|
ctrl.SetLogger(textlogger.NewLogger(tlConf))
|
||||||
|
|
||||||
tlsCfgFunc := func(cfg *tls.Config) {
|
tlsCfgFunc := func(cfg *tls.Config) {
|
||||||
cfg.MinVersion = tls.VersionTLS13
|
cfg.MinVersion = tls.VersionTLS12
|
||||||
|
cfg.MaxVersion = tls.VersionTLS12
|
||||||
|
cfg.CipherSuites = []uint16{
|
||||||
|
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
|
||||||
|
tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
|
||||||
|
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
|
||||||
|
tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
webhookOptions := webhook.Options{
|
webhookOptions := webhook.Options{
|
||||||
|
Loading…
Reference in New Issue
Block a user