diff --git a/services/submission/src/main/resources/application.yaml b/services/submission/src/main/resources/application.yaml index 24fd28bd6e..5c9a8441a2 100644 --- a/services/submission/src/main/resources/application.yaml +++ b/services/submission/src/main/resources/application.yaml @@ -61,3 +61,35 @@ management: health: probes: enabled: true + +client: + ssl: + key-password: ${SSL_SUBMISSION_KEYSTORE_PASSWORD} + key-store: ${SSL_SUBMISSION_KEYSTORE_PATH} + key-store-password: ${SSL_SUBMISSION_KEYSTORE_PASSWORD} + verification: + trust-store: ${SSL_VERIFICATION_TRUSTSTORE_PATH} + trust-store-password: ${SSL_VERIFICATION_TRUSTSTORE_PASSWORD} + +server: + ssl: + enabled: true + enabled-protocols: TLSv1.2,TLSv1.3 + protocol: TLS + ciphers: >- + TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 + TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 + TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 + TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 + TLS_DHE_DSS_WITH_AES_128_GCM_SHA256 + TLS_DHE_DSS_WITH_AES_256_GCM_SHA384 + TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 + TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 + TLS_AES_128_GCM_SHA256 + TLS_AES_256_GCM_SHA384 + TLS_AES_128_CCM_SHA256 + key-password: ${SSL_SUBMISSION_KEYSTORE_PASSWORD} + key-store: ${SSL_SUBMISSION_KEYSTORE_PATH} + key-store-password: ${SSL_SUBMISSION_KEYSTORE_PASSWORD} + key-store-provider: SUN + key-store-type: JKS