Skip to content

HTTPS clone URL

Subversion checkout URL

You can clone with
or
.
Download ZIP
Browse files

Adam suggests giving up on ciphersuite groups

  • Loading branch information...
commit a989fe51d6ba648978f0b7796f7e395f0b7b642c 1 parent 45ea1c5
@ioerror authored
Showing with 5 additions and 2 deletions.
  1. +1 −2  README
  2. +4 −0 TODO
View
3  README
@@ -1,5 +1,4 @@
-duraconf -
- A collection of hardened configuration files for SSL/TLS services
+duraconf - A collection of hardened configuration files for SSL/TLS services
Hopefully this will help you make a more informed choice about what cipher list
should be used for different applications. What you find here are recommended
View
4 TODO
@@ -9,3 +9,7 @@ It would be useful to have cipher hardened SSL/TLS configurations for:
other starttls services
openssh
+
+This is probably the optimal cipher suite for most modern sites:
+'ECDHE-RSA-AES128-SHA:ECDHE-RSA-RC4-SHA:ECDHE-RSA-AES256-SHA:ECDHE-RSA-DES-CBC3-SHA:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:EDH-RSA-DES-CBC3-SHA:AES128-SHA:RC4-SHA:AES256-SHA:DES-CBC3-SHA'
+
Please sign in to comment.
Something went wrong with that request. Please try again.