From c95ed0765e0e663e09885af12c9b7cade5e36fdd Mon Sep 17 00:00:00 2001 From: Alex Dadgar Date: Thu, 7 Jun 2018 15:30:00 -0700 Subject: [PATCH] docs for tls defaults --- website/source/docs/agent/configuration/tls.html.md | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/website/source/docs/agent/configuration/tls.html.md b/website/source/docs/agent/configuration/tls.html.md index a5f049bea..b79a1ac7e 100644 --- a/website/source/docs/agent/configuration/tls.html.md +++ b/website/source/docs/agent/configuration/tls.html.md @@ -61,9 +61,16 @@ the [Agent's Gossip and RPC Encryption](/docs/agent/encryption.html). - `tls_cipher_suites` `(array: [])` - Specifies the TLS cipher suites that will be used by the agent. Known insecure ciphers are disabled (3DES and RC4). By default, an agent is configured to use + TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, + TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305, - TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, and - TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384. + TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305, + TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, + TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, + TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, + TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, + TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 and + TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256. - `tls_min_version` `(string: "tls12")`- Specifies the minimum supported version of TLS. Accepted values are "tls10", "tls11", "tls12".