Before upgrading to apache 2.2.27 I had this line in httpd.conf
SSLProtocol -ALL +SSLv3 +TLSv1 +TLSv1.2
SSLCipherSuite ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:!LOW:!SSLv2:!EXPORT

and I was getting "A-" rating from: www.ssllabs.com

Now after upgrading to apache-2.2.27 I'm getting "C" because of weak Cipher 
Strength inclusion:

TLS_RSA_EXPORT_WITH_RC4_40_MD5 (0x3)   WEAK      40
TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5 (0x6)   WEAK      40
TLS_RSA_EXPORT_WITH_DES40_CBC_SHA (0x8)   WEAK      40
TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA (0x14)   DH 512 bits (p: 64, g: 1, Ys: 
64)   FS   WEAK      40
TLS_RSA_WITH_DES_CBC_SHA (0x9)   WEAK      56
TLS_DHE_RSA_WITH_DES_CBC_SHA (0x15)   DH 1024 bits (p: 128, g: 1, Ys: 128)   FS 
  WEAK      56

How to get rid of it?  I've tired setting in 00_default_ssl_vhost.conf

SSLProtocol all -SSLv2 -SSLv3
SSLCompression Off
SSLCipherSuite "EECDH+AESGCM EDH+AESGCM EECDH -RC4 EDH -CAMELLIA -SEED !aNULL !eNULL 
!LOW !3DES !MD5 !EXP !PSK !SRP !DSS !RC4"

or SSLProtocol -ALL +SSLv3 +TLSv1 +TLSv1.2
SSLCipherSuite ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:!LOW:!SSLv2:!EXPORT

nothing helps, I'm still getting "C" because of weak Cipher Strength inclusion.

--
Joseph

Reply via email to