Dzahn has uploaded a new change for review.

  https://gerrit.wikimedia.org/r/153978

Change subject: etherpad - use ssl_ciphersuite
......................................................................

etherpad - use ssl_ciphersuite

Change-Id: Id35d5235d2ac3141984f3fa6e5991f15c4f00030
---
M manifests/role/etherpad.pp
M templates/misc/etherpad.wikimedia.org.erb
2 files changed, 3 insertions(+), 3 deletions(-)


  git pull ssh://gerrit.wikimedia.org:29418/operations/puppet 
refs/changes/78/153978/1

diff --git a/manifests/role/etherpad.pp b/manifests/role/etherpad.pp
index 47e683c..217f6d8 100644
--- a/manifests/role/etherpad.pp
+++ b/manifests/role/etherpad.pp
@@ -25,6 +25,8 @@
         'default': {
             fail('unknown realm, should be labs or production')
         }
+
+        $ssl_settings = ssl_ciphersuite('apache-2.2', 'compat')
     }
 
     class { '::etherpad':
diff --git a/templates/misc/etherpad.wikimedia.org.erb 
b/templates/misc/etherpad.wikimedia.org.erb
index f0c61ca..a3a22c7 100644
--- a/templates/misc/etherpad.wikimedia.org.erb
+++ b/templates/misc/etherpad.wikimedia.org.erb
@@ -51,12 +51,10 @@
     ServerName <%= @etherpad_host %>
 
     SSLEngine on
-    SSLProtocol +ALL -SSLv2
-    SSLCipherSuite 
ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:ECDHE-RSA-RC4-SHA:ECDHE-ECDSA-RC4-SHA:AES128:AES256:RC4-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!3DES:!MD5:!PSK:!DH
-    SSLHonorCipherOrder on
     SSLCertificateFile <%= @etherpad_ssl_cert %>
     SSLCertificateKeyFile <%= @etherpad_ssl_key %>
     SSLCACertificatePath /etc/ssl/certs
+    <%= @ssl_settings.join("\n") %>
 
     RewriteEngine on
     ProxyVia On

-- 
To view, visit https://gerrit.wikimedia.org/r/153978
To unsubscribe, visit https://gerrit.wikimedia.org/r/settings

Gerrit-MessageType: newchange
Gerrit-Change-Id: Id35d5235d2ac3141984f3fa6e5991f15c4f00030
Gerrit-PatchSet: 1
Gerrit-Project: operations/puppet
Gerrit-Branch: production
Gerrit-Owner: Dzahn <[email protected]>

_______________________________________________
MediaWiki-commits mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/mediawiki-commits

Reply via email to