How do I disable SSL ciphers I don’t want, as many are enabled by default?
How to disable SSL ciphers in Kong-Gateway Proxy
How do I disable SSL ciphers I don’t want, as many are enabled by default?
Set ssl_cipher_suite to custom in kong.conf (or via the KONG_SSL_CIPHERS / KONG_SSL_CIPHER_SUITE environment variables) and list only the ciphers you want enabled, rather than trying to disable the ones you don’t want.
Steps
Kong allows you to configure SSL ciphers by enabling only the ones you require rather than disabling unwanted ones. Configure this by setting the ssl_cipher_suite to custom and specifying your preferred ciphers.
Set the following in your kong.conf file:
ssl_cipher_suite = customssl_ciphers = <list of ciphers to enable>Example using environment variables:
KONG_SSL_CIPHERS=ECDHE-RSA-AES256-GCM-SHA384,DHE-PSK-ARIA256-GCM-SHA384,ECDHE-RSA-CHACHA20-POLY1305
KONG_SSL_CIPHER_SUITE=custom
KONG_SSL_PROTOCOLS=TLSv1.2After restarting Kong, verify the loaded SSL ciphers with:
/usr/local/openresty/nginx/sbin/nginx -p /usr/local/kong -c nginx.conf -T | grep ssl_ciphersNote: running nginx -T on its own (without -p/-c) fails on current images because the binary’s compiled-in default config path doesn’t match Kong’s runtime layout — the -p /usr/local/kong -c nginx.conf flags are required.
For more information, see the ssl_cipher_suite and ssl_protocols property references.