SSLCipherSuite
Russell Beall
beall at usc.edu
Fri Jul 27 16:04:18 EDT 2012
Nice. Thanks for this, this is what I was looking for.
The one question I would raise about this is that because it looks quite a bit stronger, have you experienced anything more than a trickle of users who are stuck with older browsers who end up unable to connect their browsers to a website configured that way?
Thanks,
Russ.
On Jul 27, 2012, at 12:15 PM, Ian Young wrote:
>
> On 27 Jul 2012, at 19:46, Russell Beall <beall at usc.edu> wrote:
>
>> I am curious what the shib community would consider to be the ideal SSLCipherSuite setting for apache, either in front of an IdP, an SP, or both.
>
> You could try this:
>
> SSLCipherSuite ECDHE-RSA-AES128-SHA256:AES128-GCM-SHA256:RC4:HIGH:!MD5:!aNULL:!EDH:!EXPORT
>
> This is the recommendation we're giving UK federation members here:
>
> http://www.ukfederation.org.uk/content/Documents/Setup2IdPApacheHttpd
>
> It's closely based on the one worked out by Chad for the shibboleth.net sites, which is in turn based on some recommendations from www.ssllabs.com
>
>> Would this be considered sufficient, or because this is security software and subject to more stringent standards, should this be tightened in some way, for instance, by removing the +LOW configuration?
>
> I'd recommend using the ssllabs tester to see whether you're getting what you think you're getting. This only works on port 443, alas:
>
> https://www.ssllabs.com/ssltest/index.html
>
> -- Ian
>
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list