[
https://issues.apache.org/jira/browse/TS-2400?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14006313#comment-14006313
]
ASF subversion and git services commented on TS-2400:
-----------------------------------------------------
Commit f9eb372606fe1f86ba649e86539575bd30c17d07 in trafficserver's branch
refs/heads/master from [~bcall]
[ https://git-wip-us.apache.org/repos/asf?p=trafficserver.git;h=f9eb372 ]
TS-2400: Our default SSL cipher-suite advocates speed over security
> Our default SSL cipher-suite advocates speed over security
> ----------------------------------------------------------
>
> Key: TS-2400
> URL: https://issues.apache.org/jira/browse/TS-2400
> Project: Traffic Server
> Issue Type: Bug
> Components: Configuration, SSL
> Reporter: Igor Galić
> Assignee: Bryan Call
> Fix For: 5.0.0
>
>
> Our default cipher-suite advocates speed over security:
> {code}
> RC4-SHA:AES128-SHA:DES-CBC3-SHA:AES256-SHA:ALL:!aNULL:!EXP:!LOW:!MD5:!SSLV2:!NULL
> {code}
> Worse yet, it still has RC4 in there, along with some other bad defaults. RC4
> must be eradicated:
> https://blogs.technet.com/b/srd/archive/2013/11/12/security-advisory-2868725-recommendation-to-disable-rc4.aspx?Redirected=true
> We should by default advocate security, which means, we should advocate
> Perfect Forward Secrecy, which means we should also advocate OpenSSL >=
> 1.0.1e
--
This message was sent by Atlassian JIRA
(v6.2#6252)