Hi,
I have a proposal to tighten the TLS security: enable the usage of server side
cipher ordering, e.g. in smtpd.conf with
prefer-server-cipher-order yes
Current problem with a config like:
ciphers
EECDH+AES128+AESGCM:EECDH+AES256+AESGCM:EECDH+AES128+SHA256:EECDH+AES256+SHA384:EECDH+AES128+SHA:EECDH+AES256+SHA
will result on client side with:
prio ciphersuite protocols pfs
curves
1 ECDHE-RSA-AES256-GCM-SHA384 TLSv1.2 ECDH,P-384,384bits
secp384r1
2 ECDHE-RSA-AES256-SHA384 TLSv1.2 ECDH,P-384,384bits
secp384r1
3 ECDHE-RSA-AES256-SHA TLSv1,TLSv1.1,TLSv1.2 ECDH,P-384,384bits
secp384r1
4 ECDHE-RSA-AES128-GCM-SHA256 TLSv1.2 ECDH,P-384,384bits
secp384r1
5 ECDHE-RSA-AES128-SHA256 TLSv1.2 ECDH,P-384,384bits
secp384r1
6 ECDHE-RSA-AES128-SHA TLSv1,TLSv1.1,TLSv1.2 ECDH,P-384,384bits
secp384r1
which is not the "desired" order from the config.
Thanks very much,
Martin
--
You received this mail because you are subscribed to [email protected]
To unsubscribe, send a mail to: [email protected]