Skip to content

Commit c5b9b49

Browse files
committed
Require minimum TLSv1.3
1 parent 1f4f441 commit c5b9b49

File tree

1 file changed

+1
-10
lines changed

1 file changed

+1
-10
lines changed

servers/https.go

Lines changed: 1 addition & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -45,16 +45,7 @@ func NewHttpsServer(conf *conf.Conf, registry *prometheus.Registry) *http.Server
4545
Addr: conf.HttpsListen,
4646
Handler: hsts,
4747
TLSConfig: &tls.Config{
48-
// Suggested by https://ssl-config.mozilla.org/#server=go&version=1.21.5&config=intermediate
49-
MinVersion: tls.VersionTLS12,
50-
CipherSuites: []uint16{
51-
tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
52-
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
53-
tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
54-
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
55-
tls.TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,
56-
tls.TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,
57-
},
48+
MinVersion: tls.VersionTLS13,
5849
GetCertificate: func(info *tls.ClientHelloInfo) (*tls.Certificate, error) {
5950
// error out on invalid domains
6051
if !conf.Domains.IsValid(info.ServerName) {

0 commit comments

Comments
 (0)