More Info:

Ensure no HTTPS or SSL proxy load balancers permit SSL policies with weak cipher suites.

Risk Level

High

Address

Security

Compliance Standards

CISGCP, CBP, HITRUST, SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the “Load Balancers Should Not Allow Weak Cipher Suites” misconfiguration for GCP using GCP console, please follow the below steps:

  1. Open the GCP console and navigate to the Load Balancing page.

  2. Select the Load Balancer that you want to remediate.

  3. Click on the Edit button to edit the Load Balancer configuration.

  4. In the Edit Load Balancer page, scroll down to the Security section.

  5. Under the Security section, click on the Edit button next to the SSL policy field.

  6. In the Edit SSL policy page, select a SSL policy that does not allow weak cipher suites.

  7. Click on the Save button to save the changes.

  8. Once the SSL policy is updated, click on the Update button to update the Load Balancer configuration.

  9. Wait for the changes to propagate across all the resources associated with the Load Balancer.

  10. Verify that the Load Balancer is no longer allowing weak cipher suites.

By following these steps, you should be able to remediate the “Load Balancers Should Not Allow Weak Cipher Suites” misconfiguration for GCP using GCP console.