diff --git a/templates/values.yaml.tpl b/templates/values.yaml.tpl index 8333e9d..ccedbf5 100644 --- a/templates/values.yaml.tpl +++ b/templates/values.yaml.tpl @@ -75,6 +75,7 @@ controller: %{ if enable_latest_tls } ssl-protocols: "TLSv1.2 TLSv1.3" + ssl-ciphers: "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA" %{ else ~} # Config below is for old TLS versions. Specifically an incident with IE11 on # bank-admin.prisoner-money.service.justice.gov.uk. More info CP Incidents page.