Conversation
Support for TLS1.3 added Signed-off-by: Michée Lengronne <michee.lengronne@coppint.com>
08925b9 to
49374a0
Compare
controls/ssl_test.rb
Outdated
| end | ||
| end | ||
|
|
||
| control 'tls1.3' do |
There was a problem hiding this comment.
I like the addition of TLS 1.3. How to do you envision the use of TLS 1.2 control and TLS 1.3 control in parallel? Either one control will fail.
There was a problem hiding this comment.
That's a great question. Maybe, we should put another attribute to choose between the 2. TLS1.2 is still valid so we canno't remove it yet.
There was a problem hiding this comment.
I think we should test if TLS is configured properly.
- remove
control 'tls1.2' - create new
control 'tls'that verifies that it is either TLS 1.2 or TLS 1.3 - introduce an parameter to enforce a strict version, eg. tls_version
valid settings for tls_version could be auto (default), tls1.2 or tls1.3
What do you think?
There was a problem hiding this comment.
I agree. It is semantically better to regroup it on a simple control 'tls'.
Signed-off-by: Michée Lengronne <michee.lengronne@coppint.com>
|
Forget this MR, Inspec itself is not ready for TLS1.3. arlimus/sslshake#9 |
|
For cross-reference: inspec/inspec#4956 |
Support for TLS1.3 added