On Thu, Apr 14, 2016 at 08:07:43PM +0200, Martin wrote: > Hi, > > I have a proposal to tighten the TLS security: enable the usage of server > side cipher ordering, e.g. in smtpd.conf with > > prefer-server-cipher-order yes > > > Current problem with a config like: > > ciphers > EECDH+AES128+AESGCM:EECDH+AES256+AESGCM:EECDH+AES128+SHA256:EECDH+AES256+SHA384:EECDH+AES128+SHA:EECDH+AES256+SHA > > will result on client side with: > > prio ciphersuite protocols pfs > curves > 1 ECDHE-RSA-AES256-GCM-SHA384 TLSv1.2 ECDH,P-384,384bits > secp384r1 > 2 ECDHE-RSA-AES256-SHA384 TLSv1.2 ECDH,P-384,384bits > secp384r1 > 3 ECDHE-RSA-AES256-SHA TLSv1,TLSv1.1,TLSv1.2 ECDH,P-384,384bits > secp384r1 > 4 ECDHE-RSA-AES128-GCM-SHA256 TLSv1.2 ECDH,P-384,384bits > secp384r1 > 5 ECDHE-RSA-AES128-SHA256 TLSv1.2 ECDH,P-384,384bits > secp384r1 > 6 ECDHE-RSA-AES128-SHA TLSv1,TLSv1.1,TLSv1.2 ECDH,P-384,384bits > secp384r1 > > > which is not the "desired" order from the config. >
This should really be a "feature request" ticket on our ticket tracker otherwise it will get lost & forgotten ;) -- Gilles Chehade https://www.poolp.org @poolpOrg -- You received this mail because you are subscribed to [email protected] To unsubscribe, send a mail to: [email protected]
