Open patheard opened 2 years ago
Currently we're using the ELBSecurityPolicy-FS-1-2-Res-2019-08 SSL policy on our load balancer. We should look at upgrading this to ELBSecurityPolicy-FS-1-2-Res-2020-10, which is already in use by other CDS products.
ELBSecurityPolicy-FS-1-2-Res-2020-10
Impact would be dropping support for the following TLS ciphers:
Question: is the cypher used logged anywhere?
Will probably need to update the numbers
We should check to see if there is a newer cipher suite version
Summary
Currently we're using the ELBSecurityPolicy-FS-1-2-Res-2019-08 SSL policy on our load balancer. We should look at upgrading this to
ELBSecurityPolicy-FS-1-2-Res-2020-10
, which is already in use by other CDS products.Impact would be dropping support for the following TLS ciphers:
Question: is the cypher used logged anywhere?
Steps
Acceptance criteria
ELBSecurityPolicy-FS-1-2-Res-2020-10
SSL policy.