Portál AbcLinuxu, 8. května 2025 13:38
TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA (SWEET32) TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA (SWEET32) TLS_RSA_WITH_3DES_EDE_CBC_SHA (SWEET32)Moje konfigurace - Zkoušel jsem snad už vše, a ne a ne je odstranit :(
ssl_dhparam /etc/nginx/certs/dhparam-4096.pem; ssl_session_cache shared:TLS:2m; ssl_session_timeout 10m; ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384; ssl_prefer_server_ciphers off; ssl_session_tickets on; # Set HSTS to 365 days add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload' always; # Enable OCSP stapling ssl_stapling on; ssl_stapling_verify on; resolver 8.8.8.8 8.8.4.4 valid=300s; resolver_timeout 5s;NGinx používá v modu ProxyPass - paket směřuji na HTTP takže to by nemělo ovlivňovat šifry . Děkuji ...
!DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA
!DHE-RSA-DES-CBC3-SHA:!ECDHE-RSA-DES-CBC3-SHA:!DES-CBC3-SHAViz openssl 1.1.0 cyphers
ssl_prefer_server_ciphers off;
a ne ssl_prefer_server_ciphers on;
? nmap --script ssl-enum-ciphers -p 443 mail.example.com
Tak výsledek je:
443/tcp open https | ssl-enum-ciphers: | TLSv1.2: | ciphers: | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (secp256r1) - A | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (secp256r1) - A | TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 (dh 4096) - A | TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 (dh 4096) - A | compressors: | NULL | cipher preference: server |_ least strength: A
Various Browser clients have provided approximate deadlines for disabling TLS 1.0 and TLS 1.1 protocol: Browser Name Date Microsoft IE and Edge First half of 2020 Mozilla Firefox March 2020 Safari/Webkit March 2020 Google Chrome January 2020
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.