SSLCipherSuite

Russell Beall beall at usc.edu
Fri Jul 27 14:46:39 EDT 2012


I am curious what the shib community would consider to be the ideal SSLCipherSuite setting for apache, either in front of an IdP, an SP, or both.

A while back we had a tech audit where it was found that we should tighten the cipher suite to remove older insecure protocols.  They listed the insecure ciphers, but rather than just removing those, I'd like to hear what other people are using, especially if someone has researched this aspect.

A current default linux installation has ssl.conf with the following:
SSLCipherSuite ALL:!ADH:!EXPORT:!SSLv2:RC4+RSA:+HIGH:+MEDIUM:+LOW

Would this be considered sufficient, or because this is security software and subject to more stringent standards, should this be tightened in some way, for instance, by removing the +LOW configuration?

Thanks,
Russ.



More information about the users mailing list