Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove TLS 1.x from default list of supported protocols #1249

Open
1 of 2 tasks
ycombinator opened this issue Nov 12, 2024 · 1 comment
Open
1 of 2 tasks

Remove TLS 1.x from default list of supported protocols #1249

ycombinator opened this issue Nov 12, 2024 · 1 comment
Labels
good first issue Good for newcomers Team:Ecosystem Label for the Packages Ecosystem team

Comments

@ycombinator
Copy link
Contributor

ycombinator commented Nov 12, 2024

  • remove TLSv1.0 and TLSv1.1 as default supported protocols in the TLS configuration sections for for Elastic Agent.
  • remove TLSv1.0 as a supported config option entirely, so that only TLSv1.1 could be manually added back into the list of supported protocols.
@kpollich kpollich added good first issue Good for newcomers Team:Ecosystem Label for the Packages Ecosystem team labels Nov 14, 2024
@jsoriano
Copy link
Member

jsoriano commented Dec 5, 2024

  • remove TLSv1.0 and TLSv1.1 as default supported protocols in the TLS configuration sections for for Elastic Agent.

Marking this first point as done. Package Registry relies on Go for its TLS defaults, and Go sets the minimum version by default to 1.2 since Go 1.22.

It would be pending to remove 1.0 as a valid option from here:

"1.0": tls.VersionTLS10,

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
good first issue Good for newcomers Team:Ecosystem Label for the Packages Ecosystem team
Projects
None yet
Development

No branches or pull requests

3 participants