diff --git a/Dockerfile b/Dockerfile index c01df59..74433ee 100644 --- a/Dockerfile +++ b/Dockerfile @@ -73,9 +73,9 @@ ENV DEBUG="${DEBUG}" \ TOMCAT_KEYSTORE_FORMAT="PKCS12" \ TOMCAT_KEYSTORE_ALIAS="tomcat" \ \ - TOMCAT_SSL_CIPHERS="HIGH:!ADH:!EXP:!SSLv2:!SSLv3:!MEDIUM:!LOW:!NULL:!aNULL" \ + TOMCAT_SSL_CIPHERS="HIGH:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!kRSA" \ TOMCAT_SSL_PROTOCOL="TLS" \ - TOMCAT_SSL_ENABLED_PROTOCOLS="-TLSv1.3,+TLSv1.2" \ + TOMCAT_SSL_ENABLED_PROTOCOLS="TLSv1.3,TLSv1.2" \ \ TOMCAT_ENABLE_ACCESS_LOG= diff --git a/application.properties b/application.properties index d9551c5..973c686 100644 --- a/application.properties +++ b/application.properties @@ -121,8 +121,8 @@ server.http2.enabled=true server.ssl.enabled=true -server.ssl.ciphers=${TOMCAT_SSL_CIPHERS:-HIGH:!ADH:!EXP:!SSLv2:!SSLv3:!MEDIUM:!LOW:!NULL:!aNULL} -server.ssl.enabled-protocols=${TOMCAT_SSL_ENABLED_PROTOCOLS:-TLSv1.3,+TLSv1.2} +server.ssl.ciphers=${TOMCAT_SSL_CIPHERS:-HIGH:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!kRSA} +server.ssl.enabled-protocols=${TOMCAT_SSL_ENABLED_PROTOCOLS:-TLSv1.3,TLSv1.2} server.ssl.protocol=${TOMCAT_SSL_PROTOCOL:-TLS}