Skip to content
This repository has been archived by the owner on May 16, 2023. It is now read-only.

Fix SSL defaults #564

Merged
merged 2 commits into from
Jun 12, 2020
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 32 additions & 0 deletions services/submission/src/main/resources/application.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -61,3 +61,35 @@ management:
health:
probes:
enabled: true

client:
ssl:
key-password: ${SSL_SUBMISSION_KEYSTORE_PASSWORD}
key-store: ${SSL_SUBMISSION_KEYSTORE_PATH}
key-store-password: ${SSL_SUBMISSION_KEYSTORE_PASSWORD}
verification:
trust-store: ${SSL_VERIFICATION_TRUSTSTORE_PATH}
trust-store-password: ${SSL_VERIFICATION_TRUSTSTORE_PASSWORD}

server:
ssl:
enabled: true
enabled-protocols: TLSv1.2,TLSv1.3
protocol: TLS
ciphers: >-
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
TLS_DHE_DSS_WITH_AES_128_GCM_SHA256
TLS_DHE_DSS_WITH_AES_256_GCM_SHA384
TLS_DHE_RSA_WITH_AES_128_GCM_SHA256
TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
TLS_AES_128_GCM_SHA256
TLS_AES_256_GCM_SHA384
TLS_AES_128_CCM_SHA256
key-password: ${SSL_SUBMISSION_KEYSTORE_PASSWORD}
key-store: ${SSL_SUBMISSION_KEYSTORE_PATH}
key-store-password: ${SSL_SUBMISSION_KEYSTORE_PASSWORD}
key-store-provider: SUN
key-store-type: JKS