1 |
Before upgrading to apache 2.2.27 I had this line in httpd.conf |
2 |
SSLProtocol -ALL +SSLv3 +TLSv1 +TLSv1.2 |
3 |
SSLCipherSuite ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:!LOW:!SSLv2:!EXPORT |
4 |
|
5 |
and I was getting "A-" rating from: www.ssllabs.com |
6 |
|
7 |
Now after upgrading to apache-2.2.27 I'm getting "C" because of weak Cipher Strength inclusion: |
8 |
|
9 |
TLS_RSA_EXPORT_WITH_RC4_40_MD5 (0x3) WEAK 40 |
10 |
TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5 (0x6) WEAK 40 |
11 |
TLS_RSA_EXPORT_WITH_DES40_CBC_SHA (0x8) WEAK 40 |
12 |
TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA (0x14) DH 512 bits (p: 64, g: 1, Ys: 64) FS WEAK 40 |
13 |
TLS_RSA_WITH_DES_CBC_SHA (0x9) WEAK 56 |
14 |
TLS_DHE_RSA_WITH_DES_CBC_SHA (0x15) DH 1024 bits (p: 128, g: 1, Ys: 128) FS WEAK 56 |
15 |
|
16 |
How to get rid of it? I've tired setting in 00_default_ssl_vhost.conf |
17 |
|
18 |
SSLProtocol all -SSLv2 -SSLv3 |
19 |
SSLCompression Off |
20 |
SSLCipherSuite "EECDH+AESGCM EDH+AESGCM EECDH -RC4 EDH -CAMELLIA -SEED !aNULL !eNULL !LOW !3DES !MD5 !EXP !PSK !SRP !DSS !RC4" |
21 |
|
22 |
or |
23 |
SSLProtocol -ALL +SSLv3 +TLSv1 +TLSv1.2 |
24 |
SSLCipherSuite ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:!LOW:!SSLv2:!EXPORT |
25 |
|
26 |
nothing helps, I'm still getting "C" because of weak Cipher Strength inclusion. |
27 |
|
28 |
-- |
29 |
Joseph |