Skip to content

Commit 61e4a46

Browse files
Keep only IBM approved cipher suites
Signed-off-by: Mu Chen <[email protected]>
1 parent 77e4750 commit 61e4a46

File tree

1 file changed

+9
-14
lines changed

1 file changed

+9
-14
lines changed

main.go

Lines changed: 9 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -123,20 +123,15 @@ func startHTTPS(handler http.Handler) {
123123
CurvePreferences: []tls.CurveID{tls.CurveP521, tls.CurveP384, tls.CurveP256},
124124
PreferServerCipherSuites: true,
125125
CipherSuites: []uint16{
126-
tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
127-
tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
128-
tls.TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,
129-
tls.TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256,
130-
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
131-
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
132-
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
133-
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
134-
tls.TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,
135-
tls.TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256,
136-
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
137-
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
138-
tls.TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,
139-
tls.TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256,
126+
tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, //tls1.2 FIPS/IBM cloud approved
127+
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, //tls1.2 FIPS/IBM cloud approved
128+
tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, //tls1.2 FIPS/IBM cloud approved
129+
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, //tls1.2 FIPS/IBM cloud approved
130+
tls.TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256, //tls1.2 IBM cloud approved
131+
tls.TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256, //tls1.2 IBM cloud approved
132+
tls.TLS_AES_256_GCM_SHA384, //tls1.3 IBM cloud approved
133+
tls.TLS_AES_128_GCM_SHA256, //tls1.3 IBM cloud approved
134+
tls.TLS_CHACHA20_POLY1305_SHA256, //tls1.3 IBM cloud approved
140135
},
141136
}
142137

0 commit comments

Comments
 (0)