Gentoo Archives: gentoo-user

From: Joseph <syscon780@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] apache disable 40bit encryption
Date: Mon, 28 Apr 2014 22:03:55
Message-Id: 20140428220344.GF4129@syscon7.ed.shawcable.net
In Reply to: Re: [gentoo-user] apache disable 40bit encryption by Mick
1 On 04/28/14 21:38, Mick wrote:
2 >On Monday 28 Apr 2014 19:56:24 Joseph wrote:
3 >> How do I disable apache 40bit encryption connection to my server?
4 >> Is there a way to limit the connection to min 128-bit?
5 >
6 > http://httpd.apache.org/docs/2.2/mod/mod_ssl.html#sslciphersuite
7 >
8 > https://bettercrypto.org/static/applied-crypto-hardening.pdf
9 >
10 >--
11 >Regards,
12 >Mick
13
14 I've tried various combination in my: 00_default_ssl_vhost.conf
15
16 SSLProtocol -ALL +SSLv3 +TLSv1
17 SSLCipherSuite ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:!LOW:!SSLv2:!EXPORT
18
19 But openssl ciphers -v still lists:
20
21 EDH-RSA-DES-CBC-SHA SSLv3 Kx=DH Au=RSA Enc=DES(56) Mac=SHA1
22 EDH-DSS-DES-CBC-SHA SSLv3 Kx=DH Au=DSS Enc=DES(56) Mac=SHA1
23 DES-CBC-SHA SSLv3 Kx=RSA Au=RSA Enc=DES(56) Mac=SHA1
24 EXP-EDH-RSA-DES-CBC-SHA SSLv3 Kx=DH(512) Au=RSA Enc=DES(40) Mac=SHA1 export
25 EXP-EDH-DSS-DES-CBC-SHA SSLv3 Kx=DH(512) Au=DSS Enc=DES(40) Mac=SHA1 export
26 EXP-DES-CBC-SHA SSLv3 Kx=RSA(512) Au=RSA Enc=DES(40) Mac=SHA1 export
27 EXP-RC2-CBC-MD5 SSLv3 Kx=RSA(512) Au=RSA Enc=RC2(40) Mac=MD5 export
28 EXP-RC4-MD5 SSLv3 Kx=RSA(512) Au=RSA Enc=RC4(40) Mac=MD5 export
29
30 My default in 00_default_ssl_vhost.conf was:
31 SSLCipherSuite ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP:+eNULL
32
33 --
34 Joseph

Replies

Subject Author
Re: [gentoo-user] apache disable 40bit encryption Mick <michaelkintzios@×××××.com>