SSLCipherSuite

Russell Beall beall at usc.edu
Fri Jul 27 16:04:18 EDT 2012


Nice.  Thanks for this, this is what I was looking for.

The one question I would raise about this is that because it looks quite a bit stronger, have you experienced anything more than a trickle of users who are stuck with older browsers who end up unable to connect their browsers to a website configured that way?

Thanks,
Russ.

On Jul 27, 2012, at 12:15 PM, Ian Young wrote:

> 
> On 27 Jul 2012, at 19:46, Russell Beall <beall at usc.edu> wrote:
> 
>> I am curious what the shib community would consider to be the ideal SSLCipherSuite setting for apache, either in front of an IdP, an SP, or both.
> 
> You could try this:
> 
> SSLCipherSuite ECDHE-RSA-AES128-SHA256:AES128-GCM-SHA256:RC4:HIGH:!MD5:!aNULL:!EDH:!EXPORT
> 
> This is the recommendation we're giving UK federation members here:
> 
> http://www.ukfederation.org.uk/content/Documents/Setup2IdPApacheHttpd
> 
> It's closely based on the one worked out by Chad for the shibboleth.net sites, which is in turn based on some recommendations from www.ssllabs.com
> 
>> Would this be considered sufficient, or because this is security software and subject to more stringent standards, should this be tightened in some way, for instance, by removing the +LOW configuration?
> 
> I'd recommend using the ssllabs tester to see whether you're getting what you think you're getting.  This only works on port 443, alas:
> 
> https://www.ssllabs.com/ssltest/index.html
> 
> 	-- Ian
> 
> 
> 
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list