Bug#1040525: Lighttpd disregards ssl.dh-file setting

2023-09-10 Thread gs-bugs . debian . org
Repeating: lighttpd TLS configuration recommendations supercede the issue reported here. (https://wiki.lighttpd.net/Docs_SSL) > I now removed that cipher list (falling back to the default), and this > disabled the 2 remaining ciphers (DHE-RSA-AES256-GCM-SHA384 and > DHE-RSA-AES128-GCM-SHA256)

Bug#1040525: Lighttpd disregards ssl.dh-file setting

2023-07-10 Thread Alain Knaff
Hi, On 08/07/2023 00:51, gs-bugs.debian@gluelogic.com wrote: > ⚠ Expéditeur externe au réseau de l'Etat. Voir les consignes de sécurité sur > ctie.etat.lu. > > > > On Fri, Jul 07, 2023 at 09:28:24AM +, Alain Knaff wrote: >> Package: lighttpd >> Version: 1.4.69-1 >> >> Since our

Bug#1040525: Lighttpd disregards ssl.dh-file setting

2023-07-07 Thread gs-bugs . debian . org
On Fri, Jul 07, 2023 at 09:28:24AM +, Alain Knaff wrote: > Package: lighttpd > Version: 1.4.69-1 > > Since our upgrade to Debian 12, lighttpd now uses insecure > Diffie-Hellman parameters > c90fdaa22168c234c4c6628b80dc1cd129024e088a67cc74020bbea63 >

Bug#1040525: Lighttpd disregards ssl.dh-file setting

2023-07-07 Thread Alain Knaff
Package: lighttpd Version: 1.4.69-1 Since our upgrade to Debian 12, lighttpd now uses insecure Diffie-Hellman parameters c90fdaa22168c234c4c6628b80dc1cd129024e088a67cc74020bbea63 b139b22514a08798e3404ddef9519b3cd3a431b302b0a6df25f14374fe1356d6d5