On Thu, Apr 14, 2016 at 08:07:43PM +0200, Martin wrote:
> Hi,
> 
> I have a proposal to tighten the TLS security: enable the usage of server 
> side cipher ordering, e.g. in smtpd.conf with
> 
>     prefer-server-cipher-order yes
> 
> 
> Current problem with a config like:
> 
>     ciphers 
> EECDH+AES128+AESGCM:EECDH+AES256+AESGCM:EECDH+AES128+SHA256:EECDH+AES256+SHA384:EECDH+AES128+SHA:EECDH+AES256+SHA
> 
> will result on client side with:
> 
> prio  ciphersuite                  protocols              pfs                 
> curves
> 1     ECDHE-RSA-AES256-GCM-SHA384  TLSv1.2                ECDH,P-384,384bits  
> secp384r1
> 2     ECDHE-RSA-AES256-SHA384      TLSv1.2                ECDH,P-384,384bits  
> secp384r1
> 3     ECDHE-RSA-AES256-SHA         TLSv1,TLSv1.1,TLSv1.2  ECDH,P-384,384bits  
> secp384r1
> 4     ECDHE-RSA-AES128-GCM-SHA256  TLSv1.2                ECDH,P-384,384bits  
> secp384r1
> 5     ECDHE-RSA-AES128-SHA256      TLSv1.2                ECDH,P-384,384bits  
> secp384r1
> 6     ECDHE-RSA-AES128-SHA         TLSv1,TLSv1.1,TLSv1.2  ECDH,P-384,384bits  
> secp384r1
> 
> 
> which is not the "desired" order from the config.
> 

This should really be a "feature request" ticket on our ticket tracker
otherwise it will get lost & forgotten ;)


-- 
Gilles Chehade

https://www.poolp.org                                          @poolpOrg

-- 
You received this mail because you are subscribed to [email protected]
To unsubscribe, send a mail to: [email protected]

Reply via email to