Dzahn has uploaded a new change for review.

  https://gerrit.wikimedia.org/r/153984

Change subject: tendril - use ssl_ciphersuite
......................................................................

tendril - use ssl_ciphersuite

Change-Id: I4b8a3932ddde18d80f29e3f948185a18bd77bed3
---
M manifests/role/tendril.pp
M modules/tendril/templates/apache/tendril.wikimedia.org.erb
2 files changed, 2 insertions(+), 3 deletions(-)


  git pull ssh://gerrit.wikimedia.org:29418/operations/puppet 
refs/changes/84/153984/1

diff --git a/manifests/role/tendril.pp b/manifests/role/tendril.pp
index 453c1d0..6a9ca8a 100644
--- a/manifests/role/tendril.pp
+++ b/manifests/role/tendril.pp
@@ -6,6 +6,7 @@
     system::role { 'role::tendril': description => 'tendril server' }
 
     install_certificate{ 'tendril.wikimedia.org': }
+    $ssl_settings = ssl_ciphersuite('apache-2.2', 'compat')
 
     class { '::tendril':
         site_name     => 'tendril.wikimedia.org',
diff --git a/modules/tendril/templates/apache/tendril.wikimedia.org.erb 
b/modules/tendril/templates/apache/tendril.wikimedia.org.erb
index a848e6f..851699f 100644
--- a/modules/tendril/templates/apache/tendril.wikimedia.org.erb
+++ b/modules/tendril/templates/apache/tendril.wikimedia.org.erb
@@ -7,12 +7,10 @@
 <VirtualHost *:443>
        ServerName <%= @site_name %>
        SSLEngine On
-       SSLProtocol +ALL -SSLv2
-       SSLCipherSuite 
ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:ECDHE-RSA-RC4-SHA:ECDHE-ECDSA-RC4-SHA:AES128:AES256:RC4-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!3DES:!MD5:!PSK:!DH
-       SSLHonorCipherOrder on
        SSLCertificateFile /etc/ssl/private/tendril.wikimedia.org.pem
        SSLCertificateKeyFile /etc/ssl/private/tendril.wikimedia.org.key
        SSLCACertificateFile /etc/ssl/certs/RapidSSL_CA.pem
+    <%= @ssl_settings.join("\n") %>
        DocumentRoot <%= @docroot %>
 
        <Directory "<%= @docroot %>">

-- 
To view, visit https://gerrit.wikimedia.org/r/153984
To unsubscribe, visit https://gerrit.wikimedia.org/r/settings

Gerrit-MessageType: newchange
Gerrit-Change-Id: I4b8a3932ddde18d80f29e3f948185a18bd77bed3
Gerrit-PatchSet: 1
Gerrit-Project: operations/puppet
Gerrit-Branch: production
Gerrit-Owner: Dzahn <[email protected]>

_______________________________________________
MediaWiki-commits mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/mediawiki-commits

Reply via email to