Skip to content

Proposal to change 'phase out' TLS web configurations from warning to failed #1154

Description

@bwbroersma

The "Besluit beveiligde verbinding met overheidswebsites en -webapplicaties" is more strict in TLS than the previous 'streefbeeldafspraak':

Het NCSC maakt in de ICT-beveiligingsrichtlijnen voor Transport Layer Security (TLS) onderscheid tussen vier configuratieniveaus: «goed», «voldoende», «uit te faseren» en «onvoldoende». Het NCSC stelt dat van «uit te faseren»-instellingen bekend is dat deze fragiel zijn met het oog op de doorontwikkeling van aanvalstechnieken. Dit houdt in dat het risico bestaat dat deze instellingen in de nabije toekomst de status «onvoldoende» krijgen.

Artikel 2. Aanwijzing

Bestuursorganen als bedoeld in artikel 1:1, eerste lid, onderdeel a, van de Algemene wet bestuursrecht, beveiligen hun publiek toegankelijke websites en webapplicaties door toepassing van HTTPS en HSTS, met dien verstande dat:

a. de standaarden worden geconfigureerd overeenkomstig de instellingen die de status voldoende of goed krijgen in de TLS-richtlijnen;

(translated in UK English):

The NCSC-NL, in its ICT security guidelines for Transport Layer Security (TLS), distinguishes between four
configuration levels: «good», «sufficient», «phase out» and «insufficient». The NCSC-NL states that «phase out» configurations are are known to be fragile in view of the continued development of attack techniques. This implies that there is a risk that these institutions will receive "insufficient" status in the near future.
...

Article 2. Designation

Administrative bodies referred to in Article 1:1, paragraph 1, part a, of the General Administrative Law Act, shall secure their publicly accessible websites and web applications by applying HTTPS and HSTS, on the understanding that:

a. the standards are configured in accordance with the settings given the status sufficient or good in the TLS guidelines;

Currently scoring 100% on internet.nl could still mean the website is not in line with the Dutch law. My proposal is to change the TLS «phase out» configuration for web from a warning to failed.

BTW relevant to the 100% scoring and being fully compliant is also the scoring of RPKI and how HTTP-only sites cannot be distinguished from domains which are not reachable at all (they both error):

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    tlsIssues related to TLS, Transport Layer Security

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions