From 5a5d24da9269fff45377c0ec2170cb89846769f7 Mon Sep 17 00:00:00 2001 From: Silvio Rhatto Date: Tue, 16 Jul 2013 17:47:31 -0300 Subject: Trying a more restrictive cipher suite for dovecot --- templates/dovecot/dovecot.conf.squeeze.erb | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/templates/dovecot/dovecot.conf.squeeze.erb b/templates/dovecot/dovecot.conf.squeeze.erb index 705d868..c9b092c 100644 --- a/templates/dovecot/dovecot.conf.squeeze.erb +++ b/templates/dovecot/dovecot.conf.squeeze.erb @@ -120,7 +120,8 @@ ssl_key_file = /etc/ssl/private/cert.pem #ssl_parameters_regenerate = 168 # SSL ciphers to use -ssl_cipher_list = ALL:!LOW:!SSLv2 +# See http://www.virtualmin.com/node/25057 +ssl_cipher_list = HIGH:!LOW:!MEDIUM:!MD5:!SSL2:!EXP-ADH-DES-CBC-SHA:!EXP-EDH-RSA-DES-CBC-SHA:!EXP-DES-CBC-SHA:!EXP-EDH-RSA-DES-CBC-SHA:!EXP-ADH-DES-CBC-SHA:!EXP-DES-CBC-SHA:!ADH-AES256-SHA:!ADH-AES128-SHA:!ADH-DES-CBC3-SHA:!EXP-ADH-DES-CBC-SHA:!EXP-ADH-DES-CBC-SHA:!ADH-DES-CBC3-SHA:+TLSv1:+SSLv3:!SSLv2:+TLSv1.1:+TLSv1.2 # Show protocol level SSL errors. #verbose_ssl = no -- cgit v1.2.3