# Need to disable insecure SSL cyphers/TLS 1.1 on Elastic Agent

**URL:** <https://discuss.elastic.co/t/need-to-disable-insecure-ssl-cyphers-tls-1-1-on-elastic-agent/352051>\
**Category:** Elastic Agent\
**Tags:** fleet\
**Created:** [January 30, 2024, 4:28am UTC](https://discuss.elastic.co/t/need-to-disable-insecure-ssl-cyphers-tls-1-1-on-elastic-agent/352051 "2024-01-30T04:28:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![salemone](https://avatars.discourse-cdn.com/v4/letter/s/aca169/32.png) [@salemone](https://discuss.elastic.co/u/salemone)\
**Post date:** [January 30, 2024, 4:28am UTC](https://discuss.elastic.co/t/need-to-disable-insecure-ssl-cyphers-tls-1-1-on-elastic-agent/352051/1 "2024-01-30T04:28:43Z")

</div>

On a recent vulnerability scan we had findings for the Elastic Agent Fleet Server for having TLS 1.1 enabled along with insecure ciphers on port 8220. I have a client asking that we fix this... I added the below to elastic-agent.yml and in the advanced fleet server config on the agent policy but I get no change in TLS/Ciphers used. I used the KB article but it is still not working. I tried to enable TLS 1.0 just to see if it was reading the file and that changed nothing. If I add some random garbage to the file then Elastic Agent won't open which tells me it is the right config file. Any thoughts?

[Configure SSL/TLS for standalone Elastic Agents | Fleet and Elastic Agent Guide [8.12] | Elastic](https://www.elastic.co/guide/en/fleet/current/elastic-agent-ssl-configuration.html#common-ssl-options)

Added to elastic-agent.yml  
ssl:  
enabled: true  
cipher\_suites:  
- ECDHE-ECDSA-AES-128-GCM-SHA256  
- ECDHE-RSA-AES-128-GCM-SHA256  
- ECDHE-ECDSA-AES-256-GCM-SHA384  
- ECDHE-RSA-AES-256-GCM-SHA384  
supported\_protocols:  
- TLSv1.2  
- TLSv1.3

---

<div class="post-metadata">

**Author:** ![TiagoQueiroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tiagoqueiroz/32/107061_2.png) [@TiagoQueiroz](https://discuss.elastic.co/u/TiagoQueiroz)\
**Post date:** [January 30, 2024, 8:08am UTC](https://discuss.elastic.co/t/need-to-disable-insecure-ssl-cyphers-tls-1-1-on-elastic-agent/352051/2 "2024-01-30T08:08:25Z")

</div>

Hi @salemone

It looks like the indentation is wrong, here is the correct version:

```yaml
ssl:
  enabled: true
  cipher_suites:
    - ECDHE-ECDSA-AES-128-GCM-SHA256
    - ECDHE-RSA-AES-128-GCM-SHA256
    - ECDHE-ECDSA-AES-256-GCM-SHA384
    - ECDHE-RSA-AES-256-GCM-SHA384
  supported_protocols:
    - TLSv1.2
    - TLSv1.3

```

> If I add some random garbage to the file then Elastic Agent won't open which tells me it is the right config file.

If you add some garbage in a way that makes the YAML file invalid, yes, the Elastic-Agent will fail to start. However if it is still a valid YAML but with unknown keys, then the Elastic-Agent will just ignore those unknown keys. That seems to be the case with your example.

---

<div class="post-metadata">

**Author:** ![salemone](https://avatars.discourse-cdn.com/v4/letter/s/aca169/32.png) [@salemone](https://discuss.elastic.co/u/salemone)\
**Post date:** [January 31, 2024, 3:43pm UTC](https://discuss.elastic.co/t/need-to-disable-insecure-ssl-cyphers-tls-1-1-on-elastic-agent/352051/3 "2024-01-31T15:43:02Z")

</div>

I think mine did not copy and paste correctly to here because I didn't put it in the correct format. I copied your response and it did not change anything.

---

<div class="post-metadata">

**Author:** ![salemone](https://avatars.discourse-cdn.com/v4/letter/s/aca169/32.png) [@salemone](https://discuss.elastic.co/u/salemone)\
**Post date:** [January 31, 2024, 3:45pm UTC](https://discuss.elastic.co/t/need-to-disable-insecure-ssl-cyphers-tls-1-1-on-elastic-agent/352051/4 "2024-01-31T15:45:55Z")

</div>

On Reddit I found that adding the following to the Fleet Server config in Fleets in Kibana fixed it.

server.ssl.supported\_protocols: ["TLSv1.2", "TLSv1.3"]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2024, 3:46pm UTC](https://discuss.elastic.co/t/need-to-disable-insecure-ssl-cyphers-tls-1-1-on-elastic-agent/352051/5 "2024-02-28T15:46:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
