Hi, I'm new here.

First, I'd like to thank you for working on the L.E. client for Debian!

I'm writing to you because of the Apache SSL configuration the Let's
Encrypt package does:

The python-letsencrypt-apache package automatically includes a sample
config called "options-ssl-apache.conf".

I ran an SSL/TLS checker against a website with that SSL config. It got
an F rating on Cryptcheck [1] where the triple-DES cipher is considered
fatal as of CVE-2016-2183. [2][3]

I compared with the recommendations Mozilla gives in the SSL config
generator for an Apache 2.4.18 / OpenSSL 1.0.2g site that is considered
not too strict. Results are in [4].

I suppose that people who have their Apache configuration done by the
letsencrypt client might not dive into ciphers etc. That's why I propose
to change the sample config to a "best effort" secure default.

My git diff is below - only that I didn't know where to submit it in
this alioth thingy.

Please consider this!
Thanks and kind regards,


[1] https://tls.imirhil.fr/
[2] https://www.openssl.org/blog/blog/2016/08/24/sweet32/

--- snip ---

diff --git a/certbot_apache/options-ssl-apache.conf
index ec07a4b..ec6a68a 100644
--- a/certbot_apache/options-ssl-apache.conf
+++ b/certbot_apache/options-ssl-apache.conf
@@ -3,10 +3,11 @@
 SSLEngine on

 # Intermediate configuration, tweak to your needs
-SSLProtocol             all -SSLv2 -SSLv3
+SSLProtocol             all -SSLv3
 SSLHonorCipherOrder     on
 SSLCompression          off
+SSLSessionTickets off

 SSLOptions +StrictRequire

@@ -20,3 +21,9 @@ LogFormat "%v %h %l %u %t \"%r\" %>s %b" vhost_common

 # Always ensure Cookies have "Secure" set (JAH 2012/1)
 #Header edit Set-Cookie (?i)^(.*)(;\s*secure)??((\s*;)?(.*)) "$1;
+# recommended: OCSP Stapling
+# SSLUseStapling          on
+# SSLStaplingResponderTimeout 5
+# SSLStaplingReturnResponderErrors off
+# SSLStaplingCache        shmcb:/var/run/ocsp(128000)

Attachment: signature.asc
Description: OpenPGP digital signature

Letsencrypt-devel mailing list

Reply via email to