Skip to content

Commit c7f7629

Browse files
authored
Merge pull request #1811 from tkatila/tls-drop-additional-ciphers
tls: drop additional ciphers
2 parents 086d027 + 42c34a7 commit c7f7629

File tree

4 files changed

+1
-7
lines changed

4 files changed

+1
-7
lines changed

cmd/fpga_admissionwebhook/main.go

-2
Original file line numberDiff line numberDiff line change
@@ -60,8 +60,6 @@ func main() {
6060
cfg.CipherSuites = []uint16{
6161
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
6262
tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
63-
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
64-
tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
6563
}
6664
}
6765

cmd/operator/main.go

-2
Original file line numberDiff line numberDiff line change
@@ -140,8 +140,6 @@ func main() {
140140
cfg.CipherSuites = []uint16{
141141
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
142142
tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
143-
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
144-
tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
145143
}
146144
}
147145

cmd/sgx_admissionwebhook/main.go

-2
Original file line numberDiff line numberDiff line change
@@ -42,8 +42,6 @@ func main() {
4242
cfg.CipherSuites = []uint16{
4343
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
4444
tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
45-
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
46-
tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
4745
}
4846
}
4947

deployments/operator/default/manager_auth_proxy_patch.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ spec:
1515
- "--secure-listen-address=0.0.0.0:8443"
1616
- "--upstream=http://127.0.0.1:8080/"
1717
- "--logtostderr=true"
18-
- "--tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305"
18+
- "--tls-cipher-suites=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384"
1919
- "--v=10"
2020
ports:
2121
- containerPort: 8443

0 commit comments

Comments
 (0)