changeset 212:e1ee7a74d30f puppet-3.6

Update SSL config for newer, more secure browsers Based on https://ssl-config.mozilla.org/
author IBBoard <dev@ibboard.co.uk>
date Sat, 20 Jul 2019 16:13:52 +0100
parents 1ab81778ae9f
children ad143169b035
files modules/website/files/zzz-0-custom.conf
diffstat 1 files changed, 3 insertions(+), 3 deletions(-) [+]
line wrap: on
line diff
--- a/modules/website/files/zzz-0-custom.conf	Sun Jul 14 20:33:32 2019 +0100
+++ b/modules/website/files/zzz-0-custom.conf	Sat Jul 20 16:13:52 2019 +0100
@@ -1,6 +1,6 @@
-SSLProtocol ALL -SSLv2 -SSLv3
-SSLHonorCipherOrder On
-SSLCipherSuite ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:RSA+AESGCM:RSA+AES:!aNULL:!MD5:!DSS
+SSLProtocol             all -SSLv3 -TLSv1 -TLSv1.1
+SSLCipherSuite          ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384
+SSLHonorCipherOrder     off
 
 DirectoryIndex index.php index.html