Gentoo Archives: gentoo-user

From: Joseph <syscon780@×××××.com>
To: gentoo-user@l.g.o
Subject: [gentoo-user] apache-2.2.27 disable SSLCipherSuite LOW 40 56 bit
Date: Sun, 22 Jun 2014 01:29:37
Message-Id: 20140622012944.GA9332@syscon7
1 Before upgrading to apache 2.2.27 I had this line in httpd.conf
2 SSLProtocol -ALL +SSLv3 +TLSv1 +TLSv1.2
3 SSLCipherSuite ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:!LOW:!SSLv2:!EXPORT
4
5 and I was getting "A-" rating from: www.ssllabs.com
6
7 Now after upgrading to apache-2.2.27 I'm getting "C" because of weak Cipher Strength inclusion:
8
9 TLS_RSA_EXPORT_WITH_RC4_40_MD5 (0x3) WEAK 40
10 TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5 (0x6) WEAK 40
11 TLS_RSA_EXPORT_WITH_DES40_CBC_SHA (0x8) WEAK 40
12 TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA (0x14) DH 512 bits (p: 64, g: 1, Ys: 64) FS WEAK 40
13 TLS_RSA_WITH_DES_CBC_SHA (0x9) WEAK 56
14 TLS_DHE_RSA_WITH_DES_CBC_SHA (0x15) DH 1024 bits (p: 128, g: 1, Ys: 128) FS WEAK 56
15
16 How to get rid of it? I've tired setting in 00_default_ssl_vhost.conf
17
18 SSLProtocol all -SSLv2 -SSLv3
19 SSLCompression Off
20 SSLCipherSuite "EECDH+AESGCM EDH+AESGCM EECDH -RC4 EDH -CAMELLIA -SEED !aNULL !eNULL !LOW !3DES !MD5 !EXP !PSK !SRP !DSS !RC4"
21
22 or
23 SSLProtocol -ALL +SSLv3 +TLSv1 +TLSv1.2
24 SSLCipherSuite ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:!LOW:!SSLv2:!EXPORT
25
26 nothing helps, I'm still getting "C" because of weak Cipher Strength inclusion.
27
28 --
29 Joseph

Replies

Subject Author
Re: [gentoo-user] apache-2.2.27 disable SSLCipherSuite LOW 40 56 bit Mick <michaelkintzios@×××××.com>