# SSL Termination Security Configuration

**URL:** <https://forums.suse.com/t/ssl-termination-security-configuration/652>\
**Category:** Rancher 1.x\
**Created:** [October 8, 2015, 11:12am UTC](https://forums.suse.com/t/ssl-termination-security-configuration/652 "2015-10-08T11:12:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sdlarsen](https://avatars.discourse-cdn.com/v4/letter/s/f14d63/32.png) [@sdlarsen](https://forums.suse.com/u/sdlarsen)\
**Post date:** [October 8, 2015, 11:12am UTC](https://forums.suse.com/t/ssl-termination-security-configuration/652/1 "2015-10-08T11:12:59Z")

</div>

Hi. I’ve experimented with the SSL termination feature which works fine.  
The problem is there’s no way to configure security - what cipher suites and protocols to accept. I just ran a check from [ssllabs.com](http://ssllabs.com) and got a grade F. The culprits:

This server supports 512-bit export suites and might be vulnerable to the FREAK attack. Grade set to F.  
This server is vulnerable to the POODLE attack. If possible, disable SSL 3 to mitigate. Grade capped to C.  
This server is vulnerable to the OpenSSL CCS vulnerability (CVE-2014-0224) and exploitable. Grade set to F.  
This server accepts the RC4 cipher, which is weak. Grade capped to B.

It supports SSLv3 which is insecure and a number of weak cipher suites.

Any plans on adding configuration options for this?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [October 8, 2015, 4:11pm UTC](https://forums.suse.com/t/ssl-termination-security-configuration/652/2 "2015-10-08T16:11:53Z")

</div>

Rather than going down the road of adding configuration options to the rancher API for every setting haproxy has one by one, we will probably be doing [#1871](https://github.com/rancher/rancher/issues/1871) to let you inject arbitrary settings.

@alena we should probably have a better default ciphersuite though in the meantime since their default is awful…

---

<div class="post-metadata">

**Author:** ![alena](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/alena/32/50_2.png) [@alena](https://forums.suse.com/u/alena)\
**Post date:** [October 8, 2015, 4:34pm UTC](https://forums.suse.com/t/ssl-termination-security-configuration/652/3 "2015-10-08T16:34:16Z")

</div>

@vincent sure, will research for better options, and update the default config

---

<div class="post-metadata">

**Author:** ![sdlarsen](https://avatars.discourse-cdn.com/v4/letter/s/f14d63/32.png) [@sdlarsen](https://forums.suse.com/u/sdlarsen)\
**Post date:** [October 12, 2015, 9:19am UTC](https://forums.suse.com/t/ssl-termination-security-configuration/652/4 "2015-10-12T09:19:23Z")

</div>

@vincent - that makes sense  
@alena - probably the default should be tight, then people can loosen it as they see fit. The current default is in the don’t use this category 😄

Anyway, I’m getting along by deploying a small nginx proxy for doing the SSL termination and an internal load balancer - a little more work but it works as intended. Working my way towards running rancher in production…

Thank you for your support.

---

<div class="post-metadata">

**Author:** ![alena](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/alena/32/50_2.png) [@alena](https://forums.suse.com/u/alena)\
**Post date:** [October 12, 2015, 4:32pm UTC](https://forums.suse.com/t/ssl-termination-security-configuration/652/5 "2015-10-12T16:32:41Z")

</div>

@sdlarsen here is the Rancher github ticket for “insecure ssl” : [https://github.com/rancher/rancher/issues/2286](https://github.com/rancher/rancher/issues/2286). Please feel free to comment on a corresponding PR as well: [https://github.com/rancher/cattle/pull/937](https://github.com/rancher/cattle/pull/937)
