Update ssl_cipher list to include ECDHE-ECDSA options

For https://gitlab.com/gitlab-com/gl-infra/infrastructure/issues/5207 we received a private key which required ECDHE-ECDSA-AES128-GCM-SHA256 to be added to the list of ssl_ciphers in nginx.

We should consider adding this, and other ECDHE-ECDSA options:

$ openssl ciphers -v | awk '/ECDHE-ECDSA/ {print $1}'
ECDHE-ECDSA-CHACHA20-POLY1305
ECDHE-ECDSA-AES256-GCM-SHA384
ECDHE-ECDSA-AES256-SHA384
ECDHE-ECDSA-AES256-SHA
ECDHE-ECDSA-AES128-GCM-SHA256
ECDHE-ECDSA-AES128-SHA256
ECDHE-ECDSA-AES128-SHA
ECDHE-ECDSA-RC4-SHA
ECDHE-ECDSA-DES-CBC3-SHA

Once decided we need to update two files with the new list

  • https://gitlab.com/gitlab-org/omnibus-gitlab/blob/master/files/gitlab-cookbooks/gitlab/attributes/default.rb

  • https://gitlab.com/charts/gitlab/blob/master/values.yaml

Assignee Loading
Time tracking Loading