Hi,

I have a proposal to tighten the TLS security: enable the usage of server side 
cipher ordering, e.g. in smtpd.conf with

    prefer-server-cipher-order yes


Current problem with a config like:

    ciphers 
EECDH+AES128+AESGCM:EECDH+AES256+AESGCM:EECDH+AES128+SHA256:EECDH+AES256+SHA384:EECDH+AES128+SHA:EECDH+AES256+SHA

will result on client side with:

prio  ciphersuite                  protocols              pfs                 
curves
1     ECDHE-RSA-AES256-GCM-SHA384  TLSv1.2                ECDH,P-384,384bits  
secp384r1
2     ECDHE-RSA-AES256-SHA384      TLSv1.2                ECDH,P-384,384bits  
secp384r1
3     ECDHE-RSA-AES256-SHA         TLSv1,TLSv1.1,TLSv1.2  ECDH,P-384,384bits  
secp384r1
4     ECDHE-RSA-AES128-GCM-SHA256  TLSv1.2                ECDH,P-384,384bits  
secp384r1
5     ECDHE-RSA-AES128-SHA256      TLSv1.2                ECDH,P-384,384bits  
secp384r1
6     ECDHE-RSA-AES128-SHA         TLSv1,TLSv1.1,TLSv1.2  ECDH,P-384,384bits  
secp384r1


which is not the "desired" order from the config.

Thanks very much,
Martin

-- 
You received this mail because you are subscribed to [email protected]
To unsubscribe, send a mail to: [email protected]

Reply via email to