Skip to content

Disable DES and 3DES ciphers #1116

Open

Description

We're having a security audit and the EPR has some issues we have to cover.
One of them was disabling support for TLS v1.0 and 1.1. The other is disabling DES and 3DES ciphers to mitigate a SWEET32 attack.

As far as I can tell, even specifying the TLS supported versions was a relatively new addition.

Is there currently a way in which we can specify the allowed and forbidden ciphers, and if not do you have any plans to add that functionality in the future?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Assignees

No one assigned

    Labels

    Team:EcosystemLabel for the Packages Ecosystem team

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions