From b5c93a893a07f20f5322a95a64073f167d9dbb9a Mon Sep 17 00:00:00 2001 From: mh Date: Thu, 10 Jun 2010 03:52:26 +0200 Subject: adjust sslciphersuite to new recommendations --- files/include.d/Debian/ssl_defaults.inc | 1 + 1 file changed, 1 insertion(+) (limited to 'files/include.d/Debian/ssl_defaults.inc') diff --git a/files/include.d/Debian/ssl_defaults.inc b/files/include.d/Debian/ssl_defaults.inc index e69de29..3889cff 100644 --- a/files/include.d/Debian/ssl_defaults.inc +++ b/files/include.d/Debian/ssl_defaults.inc @@ -0,0 +1 @@ +SSLCipherSuite HIGH:MEDIUM:!aNULL:!SSLv2:@STRENGTH -- cgit v1.2.3 From 3223bb26521cd7aed97c3d5bd7df73269991639d Mon Sep 17 00:00:00 2001 From: mh Date: Sun, 12 Dec 2010 18:51:48 +0100 Subject: update to latest secure ssl directives --- files/include.d/Debian/ssl_defaults.inc | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) (limited to 'files/include.d/Debian/ssl_defaults.inc') diff --git a/files/include.d/Debian/ssl_defaults.inc b/files/include.d/Debian/ssl_defaults.inc index 3889cff..949fe58 100644 --- a/files/include.d/Debian/ssl_defaults.inc +++ b/files/include.d/Debian/ssl_defaults.inc @@ -1 +1,3 @@ -SSLCipherSuite HIGH:MEDIUM:!aNULL:!SSLv2:@STRENGTH +SSLProtocol -all +SSLv3 +TLSv1 +SSLCipherSuite HIGH:MEDIUM:!aNULL:!SSLv2:!MD5:@STRENGTH +SSLHonorCipherOrder on -- cgit v1.2.3 From a371c169c45dbd14ad3c465f8b7314b14c4ed8cb Mon Sep 17 00:00:00 2001 From: mh Date: Tue, 22 Feb 2011 22:59:51 +0100 Subject: add STS header in default ssl config --- files/include.d/Debian/ssl_defaults.inc | 3 +++ 1 file changed, 3 insertions(+) (limited to 'files/include.d/Debian/ssl_defaults.inc') diff --git a/files/include.d/Debian/ssl_defaults.inc b/files/include.d/Debian/ssl_defaults.inc index 949fe58..d1ec68d 100644 --- a/files/include.d/Debian/ssl_defaults.inc +++ b/files/include.d/Debian/ssl_defaults.inc @@ -1,3 +1,6 @@ SSLProtocol -all +SSLv3 +TLSv1 SSLCipherSuite HIGH:MEDIUM:!aNULL:!SSLv2:!MD5:@STRENGTH SSLHonorCipherOrder on + +# set STS Header +Header add Strict-Transport-Security "max-age=15768000" -- cgit v1.2.3