[packages/nginx] - update to latest intermediate compatibility https://wiki.mozilla.org/Security/Server_Side_TLS

arekm arekm at pld-linux.org
Tue Dec 16 15:56:33 CET 2014


commit 3f78dfb79298be8844fdea5c33419bc3dba0bb53
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date:   Tue Dec 16 15:56:28 2014 +0100

    - update to latest intermediate compatibility https://wiki.mozilla.org/Security/Server_Side_TLS

 nginx-standard.conf | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
---
diff --git a/nginx-standard.conf b/nginx-standard.conf
index aa337bd..b265718 100644
--- a/nginx-standard.conf
+++ b/nginx-standard.conf
@@ -42,7 +42,7 @@ http {
 		# https://wiki.mozilla.org/Security/Server_Side_TLS
 		# perfect forward secrecy
 		# ssl_prefer_server_ciphers on;
-		# ssl_ciphers "EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+SHA384 EECDH+ECDSA+SHA256 EECDH+aRSA+SHA384 EECDH+aRSA+SHA256 EECDH+aRSA+RC4 EECDH EDH+aRSA RC4 !aNULL !eNULL !LOW !3DES !MD5 !EXP !PSK !SRP !DSS +RC4 RC4";
+		# ssl_ciphers "ECDHE-RSA-AES128-GCM-SHA256 ECDHE-ECDSA-AES128-GCM-SHA256 ECDHE-RSA-AES256-GCM-SHA384 ECDHE-ECDSA-AES256-GCM-SHA384 DHE-RSA-AES128-GCM-SHA256 DHE-DSS-AES128-GCM-SHA256 kEDH+AESGCM ECDHE-RSA-AES128-SHA256 ECDHE-ECDSA-AES128-SHA256 ECDHE-RSA-AES128-SHA ECDHE-ECDSA-AES128-SHA ECDHE-RSA-AES256-SHA384 ECDHE-ECDSA-AES256-SHA384 ECDHE-RSA-AES256-SHA ECDHE-ECDSA-AES256-SHA DHE-RSA-AES128-SHA256 DHE-RSA-AES128-SHA DHE-DSS-AES128-SHA256 DHE-RSA-AES256-SHA256 DHE-DSS-AES256-SHA DHE-RSA-AES256-SHA AES128-GCM-SHA256 AES256-GCM-SHA384 AES128-SHA256 AES256-SHA256 AES128-SHA AES256-SHA AES CAMELLIA DES-CBC3-SHA !aNULL !eNULL !EXPORT !DES !RC4 !MD5 !PSK !aECDH !EDH-DSS-DES-CBC3-SHA !EDH-RSA-DES-CBC3-SHA !KRB5-DES-CBC3-SHA";
 
 		# Session resumption (caching)
 		# ssl_session_cache shared:SSL:50m;
================================================================

---- gitweb:

http://git.pld-linux.org/gitweb.cgi/packages/nginx.git/commitdiff/3f78dfb79298be8844fdea5c33419bc3dba0bb53



More information about the pld-cvs-commit mailing list