Skip to content

Commit ac43d66

Browse files
committed
Fixed ssl configuration (removed RC4)
1 parent 204ffb9 commit ac43d66

File tree

2 files changed

+7
-3
lines changed

2 files changed

+7
-3
lines changed

docker/web/httpd/conf/vhost.conf

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -104,9 +104,9 @@ CustomLog /proc/self/fd/1 dockerlog
104104
BrowserMatch "MSIE [17-9]" ssl-unclean-shutdown
105105

106106
## SSL Hardening
107-
SSLProtocol all -SSLv2 -SSLv3
107+
SSLProtocol All -SSLv2 -SSLv3
108108
SSLHonorCipherOrder on
109-
SSLCipherSuite "EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+SHA384 EECDH+ECDSA+SHA256 EECDH+aRSA+SHA384 EECDH+aRSA+SHA256 EECDH+aRSA+RC4 EECDH EDH+aRSA RC4 !aNULL !eNULL !LOW !3DES !MD5 !EXP !PSK !SRP !DSS"
110109
SSLCompression off
110+
SSLCipherSuite 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA'
111111

112112
</VirtualHost>

docker/web/nginx/conf/vhost.conf

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,11 @@ server {
5050
root "<DOCUMENT_ROOT>";
5151
index <DOCUMENT_INDEX>;
5252

53-
ssl on;
53+
ssl on;
54+
ssl_protocols TLSv1 TLSv1.1 TLSv1.2; # not possible to do exclusive
55+
ssl_ciphers 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA';
56+
ssl_prefer_server_ciphers on;
57+
5458
ssl_certificate /etc/nginx/ssl/server.crt;
5559
ssl_certificate_key /etc/nginx/ssl/server.key;
5660

0 commit comments

Comments
 (0)