etquia
Version:
Dummy package for the grpc-node repository
212 lines (206 loc) • 6.62 kB
text/typescript
// Original file: deps/envoy-api/envoy/extensions/transport_sockets/tls/v3/common.proto
// Original file: deps/envoy-api/envoy/extensions/transport_sockets/tls/v3/common.proto
export enum _envoy_extensions_transport_sockets_tls_v3_TlsParameters_TlsProtocol {
/**
* Envoy will choose the optimal TLS version.
*/
TLS_AUTO = 0,
/**
* TLS 1.0
*/
TLSv1_0 = 1,
/**
* TLS 1.1
*/
TLSv1_1 = 2,
/**
* TLS 1.2
*/
TLSv1_2 = 3,
/**
* TLS 1.3
*/
TLSv1_3 = 4,
}
export interface TlsParameters {
/**
* Minimum TLS protocol version. By default, it's ``TLSv1_2`` for clients and ``TLSv1_0`` for
* servers.
*/
'tls_minimum_protocol_version'?: (_envoy_extensions_transport_sockets_tls_v3_TlsParameters_TlsProtocol | keyof typeof _envoy_extensions_transport_sockets_tls_v3_TlsParameters_TlsProtocol);
/**
* Maximum TLS protocol version. By default, it's ``TLSv1_2`` for clients and ``TLSv1_3`` for
* servers.
*/
'tls_maximum_protocol_version'?: (_envoy_extensions_transport_sockets_tls_v3_TlsParameters_TlsProtocol | keyof typeof _envoy_extensions_transport_sockets_tls_v3_TlsParameters_TlsProtocol);
/**
* If specified, the TLS listener will only support the specified `cipher list
* <https://commondatastorage.googleapis.com/chromium-boringssl-docs/ssl.h.html#Cipher-suite-configuration>`_
* when negotiating TLS 1.0-1.2 (this setting has no effect when negotiating TLS 1.3).
*
* If not specified, a default list will be used. Defaults are different for server (downstream) and
* client (upstream) TLS configurations.
*
* In non-FIPS builds, the default server cipher list is:
*
* .. code-block:: none
*
* [ECDHE-ECDSA-AES128-GCM-SHA256|ECDHE-ECDSA-CHACHA20-POLY1305]
* [ECDHE-RSA-AES128-GCM-SHA256|ECDHE-RSA-CHACHA20-POLY1305]
* ECDHE-ECDSA-AES128-SHA
* ECDHE-RSA-AES128-SHA
* AES128-GCM-SHA256
* AES128-SHA
* ECDHE-ECDSA-AES256-GCM-SHA384
* ECDHE-RSA-AES256-GCM-SHA384
* ECDHE-ECDSA-AES256-SHA
* ECDHE-RSA-AES256-SHA
* AES256-GCM-SHA384
* AES256-SHA
*
* In builds using :ref:`BoringSSL FIPS <arch_overview_ssl_fips>`, the default server cipher list is:
*
* .. code-block:: none
*
* ECDHE-ECDSA-AES128-GCM-SHA256
* ECDHE-RSA-AES128-GCM-SHA256
* ECDHE-ECDSA-AES128-SHA
* ECDHE-RSA-AES128-SHA
* AES128-GCM-SHA256
* AES128-SHA
* ECDHE-ECDSA-AES256-GCM-SHA384
* ECDHE-RSA-AES256-GCM-SHA384
* ECDHE-ECDSA-AES256-SHA
* ECDHE-RSA-AES256-SHA
* AES256-GCM-SHA384
* AES256-SHA
*
* In non-FIPS builds, the default client cipher list is:
*
* .. code-block:: none
*
* [ECDHE-ECDSA-AES128-GCM-SHA256|ECDHE-ECDSA-CHACHA20-POLY1305]
* [ECDHE-RSA-AES128-GCM-SHA256|ECDHE-RSA-CHACHA20-POLY1305]
* ECDHE-ECDSA-AES256-GCM-SHA384
* ECDHE-RSA-AES256-GCM-SHA384
*
* In builds using :ref:`BoringSSL FIPS <arch_overview_ssl_fips>`, the default client cipher list is:
*
* .. code-block:: none
*
* ECDHE-ECDSA-AES128-GCM-SHA256
* ECDHE-RSA-AES128-GCM-SHA256
* ECDHE-ECDSA-AES256-GCM-SHA384
* ECDHE-RSA-AES256-GCM-SHA384
*/
'cipher_suites'?: (string)[];
/**
* If specified, the TLS connection will only support the specified ECDH
* curves. If not specified, the default curves will be used.
*
* In non-FIPS builds, the default curves are:
*
* .. code-block:: none
*
* X25519
* P-256
*
* In builds using :ref:`BoringSSL FIPS <arch_overview_ssl_fips>`, the default curve is:
*
* .. code-block:: none
*
* P-256
*/
'ecdh_curves'?: (string)[];
}
export interface TlsParameters__Output {
/**
* Minimum TLS protocol version. By default, it's ``TLSv1_2`` for clients and ``TLSv1_0`` for
* servers.
*/
'tls_minimum_protocol_version': (keyof typeof _envoy_extensions_transport_sockets_tls_v3_TlsParameters_TlsProtocol);
/**
* Maximum TLS protocol version. By default, it's ``TLSv1_2`` for clients and ``TLSv1_3`` for
* servers.
*/
'tls_maximum_protocol_version': (keyof typeof _envoy_extensions_transport_sockets_tls_v3_TlsParameters_TlsProtocol);
/**
* If specified, the TLS listener will only support the specified `cipher list
* <https://commondatastorage.googleapis.com/chromium-boringssl-docs/ssl.h.html#Cipher-suite-configuration>`_
* when negotiating TLS 1.0-1.2 (this setting has no effect when negotiating TLS 1.3).
*
* If not specified, a default list will be used. Defaults are different for server (downstream) and
* client (upstream) TLS configurations.
*
* In non-FIPS builds, the default server cipher list is:
*
* .. code-block:: none
*
* [ECDHE-ECDSA-AES128-GCM-SHA256|ECDHE-ECDSA-CHACHA20-POLY1305]
* [ECDHE-RSA-AES128-GCM-SHA256|ECDHE-RSA-CHACHA20-POLY1305]
* ECDHE-ECDSA-AES128-SHA
* ECDHE-RSA-AES128-SHA
* AES128-GCM-SHA256
* AES128-SHA
* ECDHE-ECDSA-AES256-GCM-SHA384
* ECDHE-RSA-AES256-GCM-SHA384
* ECDHE-ECDSA-AES256-SHA
* ECDHE-RSA-AES256-SHA
* AES256-GCM-SHA384
* AES256-SHA
*
* In builds using :ref:`BoringSSL FIPS <arch_overview_ssl_fips>`, the default server cipher list is:
*
* .. code-block:: none
*
* ECDHE-ECDSA-AES128-GCM-SHA256
* ECDHE-RSA-AES128-GCM-SHA256
* ECDHE-ECDSA-AES128-SHA
* ECDHE-RSA-AES128-SHA
* AES128-GCM-SHA256
* AES128-SHA
* ECDHE-ECDSA-AES256-GCM-SHA384
* ECDHE-RSA-AES256-GCM-SHA384
* ECDHE-ECDSA-AES256-SHA
* ECDHE-RSA-AES256-SHA
* AES256-GCM-SHA384
* AES256-SHA
*
* In non-FIPS builds, the default client cipher list is:
*
* .. code-block:: none
*
* [ECDHE-ECDSA-AES128-GCM-SHA256|ECDHE-ECDSA-CHACHA20-POLY1305]
* [ECDHE-RSA-AES128-GCM-SHA256|ECDHE-RSA-CHACHA20-POLY1305]
* ECDHE-ECDSA-AES256-GCM-SHA384
* ECDHE-RSA-AES256-GCM-SHA384
*
* In builds using :ref:`BoringSSL FIPS <arch_overview_ssl_fips>`, the default client cipher list is:
*
* .. code-block:: none
*
* ECDHE-ECDSA-AES128-GCM-SHA256
* ECDHE-RSA-AES128-GCM-SHA256
* ECDHE-ECDSA-AES256-GCM-SHA384
* ECDHE-RSA-AES256-GCM-SHA384
*/
'cipher_suites': (string)[];
/**
* If specified, the TLS connection will only support the specified ECDH
* curves. If not specified, the default curves will be used.
*
* In non-FIPS builds, the default curves are:
*
* .. code-block:: none
*
* X25519
* P-256
*
* In builds using :ref:`BoringSSL FIPS <arch_overview_ssl_fips>`, the default curve is:
*
* .. code-block:: none
*
* P-256
*/
'ecdh_curves': (string)[];
}