forked from mirrors/nixpkgs
httpd: Disable insecure protocols/ciphers by default
This makes us resistant to FREAK and similar attacks.
This commit is contained in:
parent
7b2adc0039
commit
8cb3e3b864
|
@ -171,6 +171,9 @@ let
|
|||
|
||||
SSLRandomSeed startup builtin
|
||||
SSLRandomSeed connect builtin
|
||||
|
||||
SSLProtocol All -SSLv2 -SSLv3
|
||||
SSLCipherSuite HIGH:MEDIUM:!aNULL:!MD5:!EXP
|
||||
'';
|
||||
|
||||
|
||||
|
|
Loading…
Reference in a new issue