Skip to content

CIS Benchmark recommends use of weak ciphers #710

Closed Answered by lizrice
pjbgf asked this question in Questions and Help
Discussion options

You must be logged in to vote

We have test files that reflect different versions of the CIS benchmark, and we want those files to reflect the benchmark as closely as possible. We wait until the CIS benchmark is updated before we take changes like this into the test files.

That said, I agree with the idea of recommending not to use these ciphers, and there have been other cases where the benchmark recommendations are incorrect or outdated (pending a new version).

I am wondering about having an additional set of test files, called something like edge or community (instead of cis-1.x) where we could include improvements like this. The benefit is that we can bring changes to the community more quickly. The downside is tha…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by pjbgf
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #710 on October 03, 2020 10:12.