Dzahn has uploaded a new change for review.

  https://gerrit.wikimedia.org/r/153977

Change subject: stats.wm.org - use ssl_ciphersuite
......................................................................

stats.wm.org - use ssl_ciphersuite

Change-Id: I0cb4100a527b7cabb3f0e548d942959bfcf93c0d
---
M manifests/misc/statistics.pp
M templates/apache/sites/stats.wikimedia.org.erb
2 files changed, 3 insertions(+), 3 deletions(-)


  git pull ssh://gerrit.wikimedia.org:29418/operations/puppet 
refs/changes/77/153977/1

diff --git a/manifests/misc/statistics.pp b/manifests/misc/statistics.pp
index d8f76bb..4892dbe 100644
--- a/manifests/misc/statistics.pp
+++ b/manifests/misc/statistics.pp
@@ -309,6 +309,8 @@
 
     install_certificate{ $site_name: }
 
+    $ssl_settings = ssl_ciphersuite('apache-2.2', 'compat')
+
     file { '/etc/apache2/sites-enabled/stats.wikimedia.org':
         ensure  => 'present',
         mode    => '0444',
diff --git a/templates/apache/sites/stats.wikimedia.org.erb 
b/templates/apache/sites/stats.wikimedia.org.erb
index a489360..6c328b3 100644
--- a/templates/apache/sites/stats.wikimedia.org.erb
+++ b/templates/apache/sites/stats.wikimedia.org.erb
@@ -82,12 +82,10 @@
     RewriteRule ^(.*)$ https://stats.wikimedia.org$1 [R=301,L]
 
     SSLEngine on
-    SSLProtocol +ALL -SSLv2
-    SSLCipherSuite 
ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:ECDHE-RSA-RC4-SHA:ECDHE-ECDSA-RC4-SHA:AES128:AES256:RC4-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!3DES:!MD5:!PSK:!DH
-    SSLHonorCipherOrder on
     SSLCertificateFile    /etc/ssl/certs/stats.wikimedia.org.pem
     SSLCertificateKeyFile /etc/ssl/private/stats.wikimedia.org.key
     SSLCertificateChainFile /etc/ssl/certs/stats.wikimedia.org.chained.pem
+    <%= @ssl_settings.join("\n") %>
 
     # Settings for geowiki's private data
     <Directory "<%= 
scope.lookupvar('misc::statistics::sites::stats::geowiki_private_directory') 
%>">

-- 
To view, visit https://gerrit.wikimedia.org/r/153977
To unsubscribe, visit https://gerrit.wikimedia.org/r/settings

Gerrit-MessageType: newchange
Gerrit-Change-Id: I0cb4100a527b7cabb3f0e548d942959bfcf93c0d
Gerrit-PatchSet: 1
Gerrit-Project: operations/puppet
Gerrit-Branch: production
Gerrit-Owner: Dzahn <[email protected]>

_______________________________________________
MediaWiki-commits mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/mediawiki-commits

Reply via email to